Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Trying to open my account via the website just redirects me back to the app — which still doesn’t work.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
b54c53e02654b723a435cd3e97a48135df4d9e2640c054245d2f98d5e9f853ff
Signature (Ed25519, base64)
lW9lfcJpRvEIAhNrj+kM9ZrFoE+5B06lgGBZfZkVDn03LzypgsXz1ATvM41jYUjNXXc7LOTVsnBrW/294CIpCw==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["b54c71ffa71f96a0979b55b0dd3f2d0922e818f17403950004913ac9b91d5c25","05358a6d86a378926d615664b919c89ce84cb6d52e4b83696da704b425bdd9a2","989ded991d8c6e12fc0fd33f65e672344546df14d95e3244511efa884ec36b5e","4da1055ccdb28192f5de6a7f9164144a2a836a73de8baee7e59a8c178543d271","aba9168565fd716803eff272db35f01ef4713a75b3c38114862b5143c1cfc70d","8d891134e60426fd1fdcfb3b5a88b0cd581609035996f60c3859d29ab32a3f69","27bc39c3aca42e719dd59d68d45ab42984fa89d237761204d26128b6d503fc15","afca7d6a5c0839645c22a78fef13059da2490ba6f71ccfebb4c60d75b0d275c6","62de6551b97bf819dd77954f17b9596fb8102a049950fdb17b2fc8ad806d0343","e0fb15463145d4f2e18dee7f0f948fbc2f0858bc5b0a6f5162ce5c2d10db5acf","86c12730349fc5d6ac0f2950e37fc472c8263259c13a59ef5e1e26828166b9d7","bcaffb66f7637f1faea00b39e1b086b5c8748b956d5fec046d9c8718408ebc96","27978d996981aec54e7305bc9bddff422c8ed02487f8eaef12f84d0b2ba90b9f","537f00dd60bfbd8c049786f7eae4da8a735af5b60dacd3bc1b6054b8ac3175e3","58a3dfc9ad8696e92f5fc9960e9c6bc4cc04e270091b574a948593298b33d1f5"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"theme:atupri/ordering/en","quote":"Trying to open my account via the website just redirects me back to the app — which still doesn’t work.","rating":1,"review_date":"2026-04-02","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.atupri.myatupri","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.