Sitemap validation says: password-protected

If you click "Validate" on the Sitemap card under Settings → Google Tools → Sitemap and see:

⚠️ Storefront is password-protected. Disable the password in Shopify Admin → Online Store → Preferences → Restrict store access, then re-validate.

It means your storefront is currently behind Shopify's password gate. Search engines (and our sitemap validator) can't reach it.

Why this happens

  • Dev stores — every Shopify development store has password protection enabled by default. You can't submit a sitemap until you disable it.
  • Live stores during a relaunch — merchants sometimes re-enable the password to hide a redesign. Sitemap submission breaks while it's on.
  • Plan downgrades — if your Shopify plan is paused, the password gate auto-engages.

How to fix

  1. Shopify Admin → Online Store → Preferences.
  2. Scroll to "Restrict store access".
  3. Uncheck the "Restrict access to visitors with the password" option.
  4. Save.
  5. Return to RankEngine Settings → re-validate the sitemap.

If you ONLY want to hide your storefront from public search engines but keep it visible to logged-in customers, use Shopify's built-in <meta name="robots" content="noindex"> instead — that's a soft signal, not a hard gate.

What if I'm on a dev store and DON'T want to disable?

You can't submit a sitemap to Google for a password-protected dev store — Google's crawler can't reach it. Workaround:

  • Disable password temporarily for sitemap submission (~5 min).
  • Submit to Google.
  • Re-enable password.

Or wait until you're ready to launch and submit then.

Related