403 Forbidden or 429 Rate Limited in Shopify Technote TN-W21

In May 2026 Shopify notified their customers that scanners should use Web Bot Auth in future.

In late July 2026, scans of Shopify sites started showing 429 Rate Limited errors instead of the usual scan results. This is due to aggressive bot protection by Shopify aimed at uncontrolled AI bots cloning sites and flooding stores with abandoned checkouts.

In addition to AI bots, the bot protection blocks:

  • Real human customers using VPNs
  • QA tools and link checkers
  • SEO and accessibility scanners

Symptoms

  • Scans of Shopify stores have far fewer pages than expected
  • If the Errors tab is turned on, it shows 403 Forbidden or 429 Rate Limited errors
  • If only the Accessibility tab is turned on, then no results are reported (the Diagnostics link on the report shows 429 Rate Limited errors)
  • The only content on the scanned pages is the text local_rate_limited
  • No other issues are detected

Resolution

Shopify now requires Web Bot Auth signatures to authorize crawler access — each connected domain has its own unique set of signatures. This is the only method Shopify supports for authorizing crawlers — they do not support IP allowlisting or alternative authorization methods, and changes to robots.txt will not bypass Shopify’s bot protection or rate limits.

Shopify’s crawling your store support page shows how to obtain the Web Bot Auth signatures for your store from your Shopify admin page.

To add Shopify signatures to an OnDemand site:

  1. Go to Options… for the site being rate limited
  2. Go to the Crawler tab in Scan Options
  3. Select Web Bot Auth, then enter the Signature-Input and Signature values from your Shopify admin. Leave Signature-Agent as "https://shopify.com" - the quotes are part of the value
  4. Click Save

To add Shopify signatures in SortSite Desktop Professional or Developer Edition:

  1. Go to View Replays on the Check menu
  2. Click the Add Web Bot Auth… button
  3. Add the site origin - your site address without any path e.g. https://example.com
  4. Enter the Signature-Input and Signature values from your Shopify admin. Leave Signature-Agent as "https://shopify.com" - the quotes are part of the value
  5. Click Save

Shopify uses different Web Bot Auth signatures for each connected domain - even domains connected to the same store. The signature values must exactly match the domain being scanned - example.com and www.example.com are different domains and use different Web Bot Auth signatures. In most cases you want to scan your store’s primary domain, so use the primary domain as the start page in OnDemand Scan Options and enter the Shopify Web Bot Auth signatures for the primary domain in the Crawler tab.

When you create a signature in Shopify you choose how long it stays valid - the default is 30 days, and the maximum is 90 days. Web Bot Auth signatures can’t be renewed — once they expire you must create new signatures in your Shopify admin page and re-enter them. Once a signature has been saved, OnDemand and the desktop app both show its expiry date under Signature-Input, turning red once the signature has expired.

Applies To: OnDemand, SortSite Professional and Developer Edition 2026.61 and later

Last Reviewed: September 7, 2026