Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“it's good to use”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
bfab6acd6d2ede32bf9235d7e31b44fbb827e59fe5eff23bcb8230f6c82ec48e
Signature (Ed25519, base64)
viA3VOToNwJFP6aPZOLtM2wjXiTZ2G7sPgjvmdYtxD8++gRlcGbO+vhy0L6xlWJmKOcynTQo2Vh4kW+2H8wKBg==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["bfabc001948254932bc0998b818c17f9c4a1e258493fa7e2643f208fa9e7f198","77bf0c86226464782a66b69b6eda091831e58d86ead4393e9715991f58ffaf5a","d5126c412feb566e7ce614393c377e9bba82cb7bda12ab40705af3bd52f17306","d3a8e70214b5ad5182f3f9f75d3ec5c115487cc8dd5eb26a10b85e41b3820e87","28ca5ed50b9c5f9593750df819ca090ccf275c41abab43396b9ad882ce0692dc","73817428b178c655ddba968cf58f75ea71202a843c3e522e8c08a9ffb129ed9e","bcecc18fab81e0273be03c9af90055cab52e4a3dde57b1fd033fc6953c2d6380","a5b2cf60c30d80bae8cbc92276e25be212b702be349815970d1473947e0c9be6","197e2f6eec5f484c33e5632e25715ac3487613bd68b91097c112430858ae4356","ec68738fba0d7e3264e63994dc521610f17f5904d7eb6bbe4316e0819d33d644","722106df6fbbc7aa8e47379a1ed59bc3a92b92a1821e142fefe0367ae74daec4","8f5ec8180fef173ef49bba3555961699c8394cb3b56f59043b48bef17eb12eae","fbc83ea3f323a853561b2d18a7d5d816b1a8631e4674525eac3ed9b0d77501a2","ebe1651655c8b61b6b5364f1f9c2df6d3d2570b884eb1475b1f154f5054feeba","a616224c7837fee9e37cf9dfa53b6dc52945555438d928215ead84ba8ccc7b57"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:spotify/quality/en","quote":"it's good to use","rating":5,"review_date":"2026-09-20","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.spotify.music","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.