Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Login rarely works”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
d170c20c0908ed4c3b4eca09636dd513fe6a2267f054d7a2ca8232e23a80c417
Signature (Ed25519, base64)
KJ8vqMXC7jFWujEcERzPN7jWIHXMaSR+9gyq4VqslfhrHzK9AA8u3EJHSUxjplvzfVBEs4/9TasbrMOtfNmVAw==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["d170c8be224d1b3850d27c1033be8a1d271689a37bafc77ae76b81f8d86b923b","3a412f6a38f5b969c6902bd48f44da6bc73edfb0f4a676d8ab17e086da1d34e6","549130c262218fcee9110b29a5a1b8bf0557ac89b4fb43b5add024b783bad0d4","709f37369b755e17781d3b992dbae8199a4a56da413892831bfaf0e58714e33f","34c0942ea888d8ff4a715e14de641ed97765dc140dd4c4667d95d23d461d658d","6c6235eca5c4fb2c77f70a3f9bd0929be6229944d1cfabb95eebb3a03946fc82","49ccfa4925e3f92b417bc9f5decda3a146550602fa8ba3a5ae1dc3a518052115","3e116aec49fc255bb5bc2a9848d7d13795cf682b3445f91898f51a3925950e2d","ae82af297fa62b8143ea54eefe99b61443e10d44405a9f80079017dedf927d4a","afcbb6b1f67dfb1bff60df00622b5552f68aa81c7dfc27c87791c7f6e8df1dde","1d9405e14643af107c29759ed9a24a4b18aeab1b3e8759243d7815e5613d437a","4c50ad53b7f499e0679555fac955a3a7f15d25b2f16f07f89bffb825c220a814","f798c0971d32a6ae8da39cbfdd643aa26fcc32dd200aa7f9151048a02f8ece59","537f00dd60bfbd8c049786f7eae4da8a735af5b60dacd3bc1b6054b8ac3175e3","58a3dfc9ad8696e92f5fc9960e9c6bc4cc04e270091b574a948593298b33d1f5"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"theme:atupri/service/en","quote":"Login rarely works","rating":1,"review_date":"2026-02-16","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.atupri.myatupri","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.