Scanning pages with Web Bot Auth SortSite Desktop Manual

Shopify now requires Web Bot Auth signatures to authorize crawler access — each connected domain has its own unique set of signatures. This is the only method Shopify supports for authorizing crawlers — they do not support IP allowlisting or alternative authorization methods, and changes to robots.txt will not bypass Shopify’s bot protection or rate limits.

Shopify’s crawling your store support page shows how to obtain the Web Bot Auth signatures for your store from your Shopify admin page.

Shopify uses different Web Bot Auth signatures for each connected domain - even domains connected to the same store. The signature values must exactly match the domain being scanned - example.com and www.example.com are different domains and have different Web Bot Auth signatures.

To add Web Bot Auth signatures for a site:

  1. Go to View Replays on the Check menu
  2. Click the Add Web Bot Auth… button
  3. Add the address of your domain as the Origin, then enter the Signature-Input and Signature values from your Shopify admin and set Signature-Agent to "https://shopify.com" (including the quotes)
  4. Click Save

To update or pause Web Bot Auth signatures:

  1. Go to View Replays on the Check menu
  2. Click Settings… on the Options menu next to the Web Bot Auth headers.
  3. Update the Signature-Input and Signature values from your Shopify admin (changes to these must always be paired).
  4. To pause playback of these headers select the Inactive radio button.
  5. To resume playback of these headers select the Active radio button.
  6. To delete Web Bot Auth headers permanently, select Delete headers on the Options menu next to the Web Bot Auth headers.