Google can crawl a member-only product page only if robots.txt allows the URL and the server returns content without a login. If the page returns a 401 or redirects to a sign-in screen, Googlebot gets no product content. Blocked URLs can still appear in results as bare links, so robots.txt is not a hiding tool.

That answer sounds simple, but the mechanism has three separate stages — crawling, rendering, and indexing — and member-only pages often fail at a different stage than store owners assume. This guide explains what Googlebot actually receives, how to test it, and where the real trade-offs sit for retailers in the UK and US.

What does Googlebot actually receive on a member-only product page?

When Googlebot fetches a URL, it first reads your robots.txt file. If the URL is disallowed, Googlebot skips the HTTP request entirely and does not render JavaScript from that page (Official source). If the URL is allowed, Googlebot makes the request and receives whatever your server returns.

For a member-only product page, the server response is the decisive factor. Three common patterns exist:

  • Hard gate with 401. The server returns HTTP 401 Unauthorized. Google's JavaScript SEO guidance notes that Googlebot skips disallowed URLs and does not render JavaScript from blocked pages (Official source). Googlebot records the page as inaccessible and moves on. No product content is indexed.
  • Soft gate with redirect. The server redirects to a sign-in URL. Googlebot follows the redirect and may index the sign-in page under the original URL, which is rarely what a retailer wants.
  • Open shell with gated data. The HTML loads publicly, but prices, stock, or member pricing arrive later via an authenticated API call. Googlebot renders the public shell and sees whatever the unauthenticated API returns.

Yes. Google's robots.txt documentation states that while Google won't crawl or index content blocked by a robots.txt file, it might still find and index a disallowed URL if it is linked from other places on the web, and the URL address and potentially other publicly available information such as anchor text can still appear in Google Search results (Official source).

The same documentation states that robots.txt is not a mechanism for keeping a web page out of Google, and to keep a web page out of Google, block indexing with noindex or password-protect the page. That warning matters for member-only catalogues because internal links, sitemaps, and third-party mentions all create discovery paths.

A useful distinction: robots.txt controls crawling, not indexing. If your goal is "members only, invisible to Search," robots.txt alone does not achieve it.

What does JavaScript change for gated product content?

Google Search processes JavaScript in three phases: crawling, rendering, and indexing. Googlebot queues pages for both crawling and rendering, and it will not render JavaScript from blocked files or blocked pages (Official source).

This has a practical consequence for member-only pages built as single-page applications. If the product grid is injected by JavaScript after an authentication check, Googlebot's renderer runs without your member session. It sees the unauthenticated state. Whether that state contains useful content depends entirely on how you build the fallback.

Google's guidance notes that Googlebot parses the response for other URLs in the href attribute of HTML links and adds the URLs to the crawl queue, and that it's fine to use JavaScript to inject links into the DOM as long as such links follow the best practices for crawlable links. JavaScript-injected links can work if they follow crawlable-link best practices, but they are not a substitute for server-rendered navigation.

A diagnostic method you can run yourself

You do not need analytics access to check what Googlebot receives. Use these steps in order:

  1. Check robots.txt first. Open yourdomain.com/robots.txt and confirm whether the product URL path is disallowed for Googlebot. If it is, stop — Googlebot never makes the request.
  2. Request the URL as Googlebot. Use the URL Inspection tool in Google Search Console, or a server-side fetch with a Googlebot user agent. Record the HTTP status code and the final URL after redirects.
  3. Compare rendered HTML. Use the URL Inspection tool's rendered HTML view, or a rendering service, to see what appears after JavaScript executes. Look specifically for product names, prices, and availability.
  4. Check for indexing without crawling. Search for a distinctive phrase from the page. If the URL appears with no snippet, that is consistent with a robots.txt block plus external links.

This method tells you what Googlebot receives. It does not tell you what Google will rank, and it does not measure traffic.

Example: a hypothetical gated catalogue decision

The following is an illustrative example, not a real business case.

Imagine a UK retailer with 400 trade-only product pages. The pages sit behind a login and return 401 to unauthenticated requests. The retailer wants trade customers to find the catalogue but does not want consumer traffic.

Option A: keep the 401 and rely on direct links and email. Google indexes nothing. Discovery depends entirely on off-site channels.

Option B: publish a public category page describing product families, with a clear sign-in call to action for pricing. The public page is crawlable; the 401 pages stay gated. This creates a legitimate discovery path without exposing member pricing.

Option C: remove the gate entirely. This changes the business model, not just the SEO setup.

The decision is commercial, not technical. Google's documentation describes crawling and rendering behavior; it does not endorse any particular access model.

What are the limits and uncertainties?

Google's documentation describes crawling and rendering behaviour, not ranking outcomes. A crawlable member-only page is not guaranteed to rank, and a blocked page is not guaranteed to stay out of results if external links exist.

The documentation also does not specify how often Googlebot re-renders JavaScript-heavy pages, or how it treats authenticated API responses in every framework. Those details are not published as fixed rules, so treat any specific claim about render frequency or API handling as unverified.

For retailers building broader store foundations, the crawlability question sits alongside category structure and buying information. Two related guides cover those areas: Ecommerce SEO: build a store people can actually find and Product page SEO: the details buyers actually need.

Follow-up questions

Does a 401 status code remove a page from Google's index?

Not automatically. A 401 tells Googlebot the page is inaccessible, but the documentation does not promise immediate de-indexing. If removal matters, use noindex where the page is accessible, or password protection as Google's robots.txt guidance suggests.

Is it cloaking to show Googlebot different content from members?

Showing Googlebot different content from what users see can fall under cloaking. Serving the same public fallback to both Googlebot and logged-out users is a different pattern. The safe test is whether a logged-out human sees the same thing Googlebot sees.

SEARCH ENGINE TRENDS

Put the idea into practice.

All articles