Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“your support took me in circles with useless troubleshooting just to get nowhere”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
bb5e13b3b6b5a85d6e0b406aaa0211ecc8ed1c3b9a8b2a576820196970ecd6e4
Signature (Ed25519, base64)
yts/13C6s178KyrLz8clt11YeY27nqvbrjt7OtwQmhoxRiBpw3gAritC5FBY8e+s7D0IY0kuJAih8CeF+ANyBA==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["bb5e557a0a3ed09232b02e10d1bdf2ae7ee0b32c5808b9eee1372b0531eeff94","8a8c78ffbc4c1f3e737734260373d87dfe46d2c3874405a6e82d360818dc418e","686b7290b5bfaf36d89c6a4a8952dd2feddc4d2d1a5c959614022e35e4cff4ed","2d7031876dfa83180e977ec6ed8e7284ff3fe21cd2e8a97bf19880ea6b4cc9da","a039ebb96e9a9522e2ad6569bc1e251ef16fc670aa98589329616291997afaf4","b3f0e8b6afb6b507ec06a7361669854606e64638ff1bb27ff19ba3aa100bc478","55c783651edb60cc0ffb0dccd7222fc020072952e281b0349b18fceed9fed061","a07e95c5ebb27546f8aeb878252491a2796436d911f4c6741628fe9a6bf7bfbc","2d7981a4ae4d78ccef8c87bbe58e02c16d6369cc0cdeb47beeffaa2771aaa39d","477525235c00c65db0380b3b727e58ee56b05c9dc549e20a3c946a1aebf94032","58f0ca39a4330977a41ad919ab6658f5a70815290c86dc574b675f26a6e14b45","e31d9f62bc1945f2fff2fd8f17f37520e88de15489b867ff62948cea41d7912d","fbc83ea3f323a853561b2d18a7d5d816b1a8631e4674525eac3ed9b0d77501a2","ebe1651655c8b61b6b5364f1f9c2df6d3d2570b884eb1475b1f154f5054feeba","a616224c7837fee9e37cf9dfa53b6dc52945555438d928215ead84ba8ccc7b57"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"de","page":"theme:spotify/service/de","quote":"your support took me in circles with useless troubleshooting just to get nowhere","rating":1,"review_date":"2026-09-20","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.spotify.music","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.