Let Consent Studio Monitoring into your Shopify store
Create a crawler signature in Shopify and add it to Consent Studio, so Monitoring can scan your store again
Last updated About 3 hours ago
When do you need this?
Shopify protects stores against automated visitors. Sometimes it also blocks Consent Studio Monitoring. When that happens, your dashboard shows "Site access blocked", or a scan shows the card "Shopify Is Blocking Monitoring". Monitoring then cannot check your store for tracking technologies.
Shopify offers one supported way to let a trusted visitor in: a crawler signature. Shopify calls this feature "Crawler access" (the underlying standard is called Web Bot Auth). You create a signature in Shopify and add it to Consent Studio. Monitoring then sends the signature with every request to your store, and Shopify lets it through.
Shopify does not let store owners allowlist IP addresses. This means our Scanner IP addresses article does not apply to Shopify stores. Use the crawler signature described below instead. The IP address article is still useful for websites behind other firewalls.
Part 1: Create the signature in Shopify
In your Shopify admin, go to Online Store > Preferences and find the section Crawler access.
Click Create signature.
Fill in the form:
Name: anything descriptive, for example "Consent Studio Monitoring".
Domain: choose the same domain your store uses in Consent Studio (you can see it under Domain Settings in Consent Studio). Both the version with and the version without "www." work. A domain that is not connected to this store does not work.
Valid for: choose the longest option. Shopify allows at most 3 months.
Click Create.
Copy the three values Shopify shows you: Signature-Input, Signature and Signature-Agent. The Signature-Agent value is "https://shopify.com", including the quotes.
Good to know:
A signature applies to one domain.
A signature cannot be renewed. After it expires, you create a new one.
A signature does not give access to Shopify Checkout. Monitoring does not need checkout access.
See Shopify's guide: Crawling your store.
Part 2: Add the signature to Consent Studio
In Consent Studio, open Domain Settings (in the navigation group Domain).
Open the Access tab.
Under Crawler signature (Web Bot Auth), click Add signature.
Paste all three lines into the Signature field, each as "Name: value". For example:
Signature: sig1=:β¦: Signature-Input: sig1=(β¦) Signature-Agent: "https://shopify.com"The order does not matter, and blank lines between them are fine.
Click Save signature. A new scan starts automatically (unless one was started in the last 15 minutes). The results appear on your dashboard shortly.
Optional: click Test access. Monitoring loads your homepage the way a scan does and tells you either "Monitoring can reach your website" or "Monitoring is still blocked".
After saving, the Access tab shows a card with your domain and a status:
valid until <date> (green): everything is fine.
expires on <date> (amber): shown from 14 days before the signature expires.
expired on <date> (red): the signature no longer works. Create a new one (see Renewing your signature below).
The card also shows the last characters of the Key ID and the date the signature was added, with the buttons Replace signature, Test access and Remove.
Monitoring access is not part of the Installation wizard. Set it up under Domain Settings β Access (gear icon β Domain β Domain Settings β Access), or follow Step 5 in Shopify: How to Install Consent Studio and the steps in this article. The Access tab shows a check mark while a valid signature is saved.
Renewing your signature
Shopify signatures expire after at most 3 months. From 14 days before expiry, Consent Studio shows the recommendation "Renew your crawler signature", and you also receive it by email. To renew:
Create a new signature in Shopify (see Part 1).
On the Access tab in Consent Studio, click Replace signature and paste the new lines. The old signature is replaced.
Troubleshooting
You see an error when saving. The message names what is wrong, for example a missing line, or "This signature expired on β¦". Copy all three lines from the same signature in Shopify again and paste them.
Test access says "Monitoring is still blocked". Check that the signature was created for this store's domain, that it was not deleted in Shopify, and that it has not expired. Shopify answers an invalid signature as if the visitor was rate limited, so the message alone does not tell you which of these is the cause.
Test access says "Your website asks for a password". Your store is password protected. Add the username and password under Basic Authentication on the same Access tab.
Is this secure?
Your signature is stored encrypted and is never shown again after saving, not even to our support team. Monitoring only sends it to your store's own domain, never to other websites your store loads.