Sitemap validation says: password-protected
If you click "Validate" on the Sitemap card under Settings → Google Tools → Sitemap and see:
⚠️ Storefront is password-protected. Disable the password in Shopify Admin → Online Store → Preferences → Restrict store access, then re-validate.
It means your storefront is currently behind Shopify's password gate. Search engines (and our sitemap validator) can't reach it.
Why this happens
- Dev stores — every Shopify development store has password protection enabled by default. You can't submit a sitemap until you disable it.
- Live stores during a relaunch — merchants sometimes re-enable the password to hide a redesign. Sitemap submission breaks while it's on.
- Plan downgrades — if your Shopify plan is paused, the password gate auto-engages.
How to fix
- Shopify Admin → Online Store → Preferences.
- Scroll to "Restrict store access".
- Uncheck the "Restrict access to visitors with the password" option.
- Save.
- Return to RankEngine Settings → re-validate the sitemap.
If you ONLY want to hide your storefront from public search engines but keep it visible to logged-in customers, use Shopify's built-in <meta name="robots" content="noindex"> instead — that's a soft signal, not a hard gate.
What if I'm on a dev store and DON'T want to disable?
You can't submit a sitemap to Google for a password-protected dev store — Google's crawler can't reach it. Workaround:
- Disable password temporarily for sitemap submission (~5 min).
- Submit to Google.
- Re-enable password.
Or wait until you're ready to launch and submit then.