Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“I asked to cancel Spotify and they refused to give me a refund.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
c3a7f88325e270b10c980b14dcfca65a49bde37012ec3e37cdbc81a9c7674e3d
Signature (Ed25519, base64)
31+vAcFC3tWXohC/vgliKC4P329Og6EgWnB1HTzL9B12KDzSozRU623N1ae7eTw2kwTfQtfZvNfB4pUbpl5rDQ==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["c3a94f26ffdbef7bf86ab69d0e9fe5e86dd2c309cdb74df1b43b037a49296fc3","74346e6c1819048305f62d397c84adabb8264ecd7d50045fe1b083fa5a73679e","e3e0e22b1d2f2b7bf8238633729daac8fbc960ab6027204e080b4cbc392cd998","e28d9462f0baf338c95def5d6b579eb5dc25ff23de5285d2ec3d8ed8699dcd31","7ad5eafd0bd390ac88e7fc1cc3b248341438b91028ab335925b3776ea8d2eceb","f859e1fa1d3cf363a08c3e8c3157e22d88b39abf4ea44cdc9deeb494f8e5993c","ebfc4610bea824a461cb580a522ac00c883b766bd967c68aa9b23af7bc00026b","1f602fa3f32848c2a88741fd850921ed50770e20ad10d44acb07f44782e91a7a","023cdae2ba2f3e51c483bf68ae2b6048d46609cfb1ef391f57e7322fd4e9585b","800ab42cd73afde0f3af2d9507b1828fc4b7aad3659d3b8493f5cf27edde8bab","722106df6fbbc7aa8e47379a1ed59bc3a92b92a1821e142fefe0367ae74daec4","8f5ec8180fef173ef49bba3555961699c8394cb3b56f59043b48bef17eb12eae","fbc83ea3f323a853561b2d18a7d5d816b1a8631e4674525eac3ed9b0d77501a2","ebe1651655c8b61b6b5364f1f9c2df6d3d2570b884eb1475b1f154f5054feeba","a616224c7837fee9e37cf9dfa53b6dc52945555438d928215ead84ba8ccc7b57"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:spotify/returns/en","quote":"I asked to cancel Spotify and they refused to give me a refund.","rating":1,"review_date":"2026-09-18","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.spotify.music","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.