Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The application works excellently.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
d90b1e3eed41ad55ee4e617d3681210d607e24f0ae40752cc75e27f4948fb29a
Signature (Ed25519, base64)
Can0RFlf2d0Vob/OufLXmjqou9HgLdiJvIREEahzhn1fRe3rHBHLslZ3R6B0WiN+f/Y0vUn0X4KkQYXfgwPZCg==
Merkle root
f26292e960b34f73f9768b4afc64585e265549d794b35b8167826c2bcda92ef5
Merkle path
["d90dca4c86056ad88515f5f3b7d29088b47d7a703cdbf0c86951d76253047af8","a5a07aff6e7e15297dc493dfa9cc79b7451d7ff37d04612deb5189f8786a0fe1","126265561ec9db62818eb34f3f7346172a20e689f2c1cfd974f75787814c3126","5f1a974ff08a7b0e0d6a9f1f6150dcf5a7aa3a60b6b3d93719d1c4bcc03deaf8","e0e00c219c92be88ee02207c959a42e74ba7c013ca858fd5d05c82b222ab28c1","8ac68760b8770c36d40cc8dd469041997ca83257129516f5a5668fa5f004fd21","b965e669c24de3c1bbec87645df1e04e49179a4d33373fb58cabf9bd085a2362","b7975e7ef913df80732dd5a5afc16e9562574035423c322a7892b40cf2eb37c4","c0984c95e03c295f07a02b8d410c59735df9f70bf75844e351fe135eb7d8793a","a70e1d2f9ccffd8b729b52d378b6ed2103af85893ef32dec9842453e7f2c1aff","5a957482a39ac8356dc26bb21111830411eab29bbbb9a8dd03479b67627dbe15","88c1267a6d70047cee180b9815247bc1da5a16a96b57f3fe20a9c2533caa110d","44c8cb0eec3d4c66924c6271a9a32942cc950a307a9339cedf9246ffe3125d65","b763ea1ef84637e764decc45acddfba68cbd65e2d958f57cfeabc8af53520b04","a616224c7837fee9e37cf9dfa53b6dc52945555438d928215ead84ba8ccc7b57"]
Anchored
2026-09-23
Public log entry
search.sigstore.dev, log index 2913636507 · entry 108e9186e8c5677aea51…
Expected log hash
417fac9b806377ff48d30ded01faf8424eb98406df713fe2564ee9077747e6a6 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1790070376053","kind":"published-quote","locale":"en","page":"theme:deezer/quality/en","quote":"The application works excellently.","rating":4,"review_date":"2026-09-20","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=deezer.android.app","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f26292e960b3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.