Page indexing report · Search Console

Blocked due to unauthorized request (401)

Google asked for the page and your server replied that it needs a login. Googlebot doesn’t log in, so the page isn’t indexed.1 That’s correct for private pages and a problem for public ones. Here’s how to tell which, and how to fix it.

Updated · Based on Google’s documentation, statements from Google staff and published studies · 11 sources

Check the URL first

The checker shows whether the URL asks an ordinary visitor for a login. It can’t see what Google’s own requests get. A rule that targets Google’s IP addresses or user agent only shows up in URL Inspection and your server logs.

Free, no sign-up. Checks status, noindex, robots.txt, canonical, content and sitemap.

In 30 seconds

  • The server answered Google with a 401, a request for credentials. Google doesn’t index 4xx URLs and removes ones that were indexed.2
  • On staging sites, account pages and private areas it’s the right outcome. Just keep those URLs out of sitemaps and public links.
  • On public pages, remove the login, or for gated content let verified Google crawlers in.1
  • Verify Google by reverse and forward DNS or its published IP ranges, never by user agent alone.4

What the status means

A 401 response means “authenticate first”. Google’s report describes it as the page being blocked to Googlebot by a request for authorization, and suggests checking it by visiting the page in incognito mode.1

Google handles 401 like most other 4xx codes. It ignores any content in the response, doesn’t index the URL, and removes it from the index if it was there. It then crawls the URL less and less often.2 A 401 doesn’t slow crawling of the rest of the site.2

Where it happens

The 401 stops Google at the crawl stage, before it sees any content. Select a stage to see what happens there.

Crawl

Googlebot checks robots.txt, then requests the URL. It spaces requests out so it doesn’t overload the server.

What goes wrong: The URL is blocked, returns an error, or the server is slow, so Google backs off and crawls less.

Report statuses at this stage

Is it a problem?

The 401 comes from your own server, so it’s yours to change. Google notes that in general you can only fix issues whose Source column says Website.1

Usually fine

  • Staging, preview and development sites
  • Account, checkout and admin pages
  • Private documents and intranet pages
  • Old URLs nobody links to any more

Worth fixing

  • Public pages you want in search
  • URLs listed in your XML sitemap
  • A sudden jump in the count after a launch or deploy
  • Members-only content you want indexed

Google itself says confidential content should be password protected.7 A login blocks crawlers and people alike.6

Find the cause

Answer a few questions. Each cause is explained below.

Question 1Should people find this URL in Google without logging in?

A private URL leaked into public view

Google finds URLs through links and sitemaps. If a staging host or a private folder shows up here, something public points at it. Mueller’s advice on staging sites starts with the same point: don’t link to them.8 Keep the login and remove the references.

A login was left on the live site

Sites launched from a password-protected staging setup sometimes keep the password on some folders. Plugins that protect members’ content can also cover more URLs than intended. An incognito window shows it straight away.1

Only Google gets the 401

If the page loads for you but URL Inspection’s live test still reports a 401, a rule is treating Google’s requests differently. The live test shows the failure in the Page fetch field.3 Confirm it in your access logs by finding requests from verified Google IPs and the status they got.

Gated content you want indexed

Google’s report says to either remove the login or let Googlebot through after verifying its identity.1 Serving the full page to Google while visitors see a paywall isn’t treated as cloaking, as long as Google sees what a subscriber sees.11 The paywall markup makes that explicit.10

Where 401s come from

Pick a source to see how to recognise it. The last tab shows how to check a request really came from Google.

HTTP Basic or Digest auth

The browser shows its own grey username and password box, not a page from your site. The response is a 401 with a WWW-Authenticate header. It’s set in server config (Apache .htaccess, nginx auth_basic) or a hosting panel’s “password protect directory” option.

curl -sI https://example.com/page | grep -iE '^HTTP|www-authenticate'
# HTTP/2 401
# www-authenticate: Basic realm="Restricted"

How to fix it

  1. Open the row in the Page indexing report and switch the filter to “All submitted pages”. Those are the URLs you asked Google to index.1
  2. Inspect one URL and run the live test. Check the Page fetch result and the last crawl date.3
  3. Open the URL in a private window to see what a logged-out visitor gets.1
  4. Private URL: remove it from sitemaps and public links, and leave the login in place.
  5. Public URL: remove the login rule. Gated URL: let verified Google crawlers in and add paywall markup.10
  6. Run the live test again. If Page fetch succeeds, click Request indexing for key URLs, then Validate fix in the report.3

How long it takes

401 vs 403

Blocked due to unauthorized request (401)Blocked due to access forbidden (403)
What the server saysLog in firstYou’re not allowed
Google’s viewBlocked by a request for authorization1Googlebot never sends credentials, so the server is returning it incorrectly1
Usual causePassword protection, staging, members areasFirewall, CDN or security plugin rules
Effect on indexingThe same: not indexed, and removed if indexed before2

Questions

What does “Blocked due to unauthorized request (401)” mean?

Google requested the URL and the server answered 401, asking for credentials. Googlebot doesn’t log in, so it can’t see the page and won’t index it. Pages that were indexed and start returning 401 are removed.

Is a 401 in Search Console bad?

Not if the page is meant to be private. Logins are the right way to keep staging sites and account pages out of Google. It matters when a public page or a sitemap URL is in the row.

How do I let Googlebot past a login?

Remove the login for pages that should be public. For gated content you want indexed, serve the full page only to requests verified as Google by reverse and forward DNS or Google’s published IP ranges, and add paywall structured data. Never trust the user agent alone.

Why is my staging site showing 401 errors in Search Console?

Google found staging URLs somewhere public, often a sitemap, canonical tag or absolute link that points at the staging host. The login is working. Remove the references and Google will crawl those URLs less over time.

Should I use robots.txt instead of a password on staging?

No. robots.txt stops crawling, not indexing, and it’s easy to copy to the live site by mistake. Google’s John Mueller has recommended server-side authentication for staging servers.

What is the difference between 401 and 403 in Search Console?

401 means the server asked for credentials. 403 means it refused the request outright. Google notes that Googlebot never sends credentials, so a 403 is the server’s choice and often comes from a firewall or CDN rule.

Sources

  1. Google, “Page indexing report”, Search Console Help
  2. Google, “How HTTP status codes affect Google’s crawlers”, Google Crawling Infrastructure, updated February 2026
  3. Google, “URL Inspection tool”, Search Console Help
  4. Google, “Verify requests from Google crawlers and fetchers”, Google Crawling Infrastructure, updated March 2026
  5. Google, “Google’s common crawlers”, Google Crawling Infrastructure, updated July 2026
  6. Google, “What is Googlebot”, Search Central, updated February 2026
  7. Google, “Control the content you share on Search”, Search Central, updated December 2025
  8. John Mueller (Google), Webmaster Central hangout, reported by Search Engine Journal, September 2019
  9. Gary Illyes (Google), “Don’t use 403s or 404s for rate limiting”, Search Central Blog, February 2023
  10. Google, “Subscription and paywalled content markup”, Search Central, updated September 2026
  11. Google, “Spam policies for Google web search”, Search Central, updated August 2026