Heatmaps not capturing? Create a Shopify crawler access signature
What’s happening
Section titled “What’s happening”To build a heatmap, Propel Replays sends a crawler to visit your storefront and
take a snapshot of the page. Since May 30, 2026, Shopify applies strict limits
to automated crawlers visiting storefronts. This affects our heatmap crawler
too: Shopify blocks the visit, and instead of your page the crawler captures a
blank white page with a single line of text saying local_rate_limited.
If your heatmap’s snapshot looks like that, this is the cause. Because the snapshot failed, the heatmap can’t collect clicks either.
The fix takes about two minutes: create a crawler access signature in your Shopify admin, then paste it into Propel Replays. The signature tells Shopify that our crawler is visiting your store with your permission.
Step 1: Create a crawler access signature in Shopify
Section titled “Step 1: Create a crawler access signature in Shopify”- In your Shopify admin, go to Online Store → Preferences.
- Scroll to the Crawler access section.
- Click Create signature.
- Shopify shows three values: Signature, Signature-Input, and Signature-Agent. Keep this page open, you’ll copy all three in the next step.
For more about this Shopify feature, see Shopify’s crawler documentation.
Step 2: Add the signature to Propel Replays
Section titled “Step 2: Add the signature to Propel Replays”- In Propel Replays, go to Settings and find the Heatmap settings card.
- Click Advanced settings to expand it, then find Shopify crawler access signature.
- Paste each of the three values from Shopify into its matching field: Signature, Signature-Input, and Signature-Agent.
- Copy the values exactly as Shopify shows them. Signature-Agent is usually
"https://shopify.com", including the quotes. - Click Save.
Step 3: Recreate your heatmaps
Section titled “Step 3: Recreate your heatmaps”Heatmaps created while the crawler was blocked captured the blank
local_rate_limited page instead of your store, and they won’t fix
themselves. After saving the signature:
- For each affected heatmap, open it and use Reset, or delete it and create it again.
- New heatmaps created after saving the signature will capture normally.
Clicks start collecting once the heatmap has a good snapshot of your page.
Important: signatures expire after 3 months
Section titled “Important: signatures expire after 3 months”Shopify signatures last at most 3 months and can’t be renewed. Propel Replays shows the expiry date under the Signature-Input field in Heatmap settings.
When the signature expires, heatmap captures will start failing again. Create a new signature in your Shopify admin and paste the new values into the app, then reset any heatmaps that failed in the meantime.
Still not capturing?
Section titled “Still not capturing?”A couple of other things can block the crawler:
- Password-protected storefront: enter your storefront password in the same Heatmap settings card so the crawler can get past the password page.
- A firewall or bot protection in front of your store (for example
Cloudflare or Vercel): use the Propel crawler header token in Heatmap
settings. Generate the token, then add a firewall rule that allows requests
carrying the
x-propel-crawlerheader with that value.
If heatmaps still aren’t capturing after these steps, contact us through the in-app chat and we’ll dig in with you.