For the complete documentation index, see llms.txt. This page is also available as Markdown.

Target Setup Guide

Target is the most complex site Refract supports. On top of the usual accounts, profiles, and proxies, Target requires cookies to pass Shape (its anti-bot system), which means running a cookie harvester alongside your tasks. This guide builds the setup step by step.

Your first Target setup

To reduce fingerprinting issues and avoid the common mistakes, every new user should start with exactly this. It is also the setup that has worked best for the people we have helped:

  • A maximum of 10 tasks, on 10 unique Target accounts, one task per account per product.

  • Your local PC, not a server or RDP. Servers significantly increase Shape blocks due to common device fingerprints.

  • 2 cookie harvesters: one on Chrome, one on Brave. Use in-bot harvesters (they have been passing Shape better; set the Brave browser path on the second one), or extension instances.

  • No proxies on tasks or harvesters. Only use proxies on the monitor, with at least 1 proxy per monitor input when running multi-SKU.

  • Multi-SKU on.

  • Experiment with task and monitor delays. Some users run as low as 1000, some as high as 4000; find what works for your machine.

Once this configuration is running successfully, you can experiment with different setups.

The build order

You will do six things, in this order. Steps 1-2 are the same as every other site:

  1. Add your accounts and group them. Do not log them in from the Accounts tab.

  2. Create your profiles, one unique profile per task.

  3. Create a Target task group and set the monitor input (see Monitor Setup below).

  4. Create your tasks (see Task Creation below).

  5. Set up a cookie harvester: in-bot (recommended) or the extension.

  6. Start tasks and harvest login cookies, then keep ATC cookies running (see Log in your accounts below).

When you're ready to expand

Once the 10-task setup is running and hitting, you can scale up, with a hard ceiling:

  • Up to 30 accounts maximum, one task per account per product, running the in-bot harvester.

  • Everything stays on a local PC. This is still not a server setup.

  • Scale your harvester count to hold about 3 cookies per running task. At 30 tasks that is roughly 90 cookies banked, and remember the trade-off: the more cookies you generate, the higher your flag risk. Harvesting on residential proxies has been helping pass Shape at this scale.

  • Do not push past 30. Target is not a game of scale, and users who scale harder consistently hit less.

How Target is different

  • Two kinds of cookies: login cookies (to log accounts in) and add-to-cart cookies (to cart Shape-protected products). Both come from a harvester: the extension, the in-bot harvester, or both at once.

  • Tasks use the harvester proxy for add to cart and login. Whatever proxies your extension or in-bot harvester runs on are the proxies your tasks present to Shape.

  • Refract always checks out with the profile info in the bot. You do not need to add your shipping address or card to the Target account yourself, or with another tool. On task start, Refract makes sure the profile's info is on the account and set as the default for checkout.

  • Everything known about Shape is in the release guide. Opening a ticket will not get you more; if we knew more, it would be written there.

Target Release Guide

Prerequisites

  • Target accounts: one task per account per product. The same accounts can be run more than once across products or multi-SKU.

  • Unique profiles, one per task.

  • Proxies: ISPs on the monitor. Residential (resi) on tasks, and especially on harvesters. Yes, resis use data, but they have been passing Shape much better. On a small local setup (up to 2 harvesters), harvesting with no proxies works too; your home IP is residential.

  • A local PC. Mac is best for Shape, then local Windows. Avoid Windows servers for Target if at all possible.

  • The extension installed, or the in-bot harvester set up (or both):

Extension (Shape Generation)In-Bot (Shape Generation)

Monitor Setup

The monitor input is the product's TCIN, the number from the product URL. A URL will not work. Use ISP proxies on the monitor.

Multi-SKU is preferred on Target. With Use Multi Input on, add one product per line, with an optional price cap:

You can run the same accounts more than once for Target, but multi-SKU beats duplicating task groups: every group you duplicate doubles the cookies you need, since each running task should have 3 cookies banked. In numbers: 10 tasks in 1 group need 30 cookies. Duplicate that group and you have 20 running tasks needing 60 cookies. A third group makes it 90. Multi-SKU covers the same products with the original 30, and the more cookies you generate, the higher the likelihood you get flagged and Shape blocked.

Task Group Settings

The Target task group settings panel
The Target group panel. Hype Product ON for every Shape-protected drop.
Setting
Value
Notes

Use Multi Input

Preferred for multiple products

Formats above

Monitor Input

The product's TCIN

Monitor Proxy List

Your ISP list

Monitor Delay

3500 (default)

Price Max

Leave blank

Max price of 1 item, before tax and shipping. Blank means no cap. Whole dollars only: round up, no cents

High Stock & Pre-Orders only

OFF

ON makes the bot only go for high-stock items (10+ in the stock count) and pre-orders. Leave off by default, including for a normal potential restock

Hype Product

ON for Shape-protected drops

Required for all high-demand drops (cards, consoles, and similar). To test if a product is protected, run a task without it; if blocked, it is protected

Loop Checkouts

OFF

Optional, at your own risk; may increase flags and cancels. With multi-SKU it loops the same product until OOS, then moves to the next

Task Creation

The Target Create Tasks window
The Target Create Tasks window.

Required fields:

Setting
Value
Notes

Profiles

Your Profile Group

One unique profile per task

Task Proxy List

Your residential list

Resis have been passing Shape much better. Leave blank for localhost (not recommended)

Accounts

Your Account Group

Every task needs an account

Retry Delay

3500 (recommended)

Experimenting with lower delays is fine; defaults are the baseline

Task Qty

1

Tasks per profile. About 30 tasks total is the suggested max at this time; see How many tasks should you run?

Item Quantity

1

A ceiling, not an exact number: the task goes for the max it can get, up to what you set. See How Item Quantity works

Optional fields:

Setting
Notes

Match account to profiles (by email)

Pairs accounts to profiles with the same email

In-Store Pickup

Required for in-store-only products

Use Target Circle Balance

Uses rewards at checkout if available

Login with OTP

Logs in with a code sent to the account email; may pass login antibot better. Pair it with IMAP or enter codes in the pop-up

Add Extra Product

Needed for items under $35: Refract only checks out with free shipping, and Target's free shipping needs a $35+ cart (tasks show "Product Not Supported" without it). Adds a filler product (set a custom item, like a Lego set) and cancels JUST THE LEGO after checkout. Set the item yourself; left blank the bot picks a cheap one that may not clear $35. Also designed to help with Item Demand cancels; how much that helps is unknown

Log in your accounts

Do not log in from the Accounts tab. Target accounts log in with cookies:

1

Create and start your tasks

Tasks will sit on Waiting for Cookies (Login). That is your cue to harvest.

2

Harvest login cookies

Follow the extension guide to harvest login cookies on the Target account page. Tasks log in and move on as cookies arrive.

Optionally use Login with OTP (with IMAP) for the lowest-security login path.

3

Switch to ATC cookies

Once no tasks show Waiting for Cookies (Login), switch to harvesting add-to-cart cookies, and keep that running as long as tasks run. First-time logins and accounts needing a profile update will show Waiting for Cookies (Product) until ATC cookies arrive.

Sessions logged in via the extension last days or weeks. Logging in from the Accounts tab is not recommended and produces much shorter sessions.

Cookies: the rules that matter

  • There is no one-size-fits-all fix for Shape blocks. Shape scores your whole setup (device, browser, proxies, cookie volume, and the product's security level) together. What fixes one user's blocks does nothing for another's.

  • Target: about 3 cookies per running task banked. Not a giant pile. Generating far more raises your own flag risk.

  • Quality beats quantity. A small batch of high-quality cookies carts; a huge stash of flagged ones does not. If you are not carting with 3 cookies per task, more bad cookies will not fix it. Improve the setup (device, browser, proxies) instead.

  • Harvest on any in-stock product. It does not matter what product you harvest on, as long as it is in stock and available for shipping. If harvesting suddenly stops producing cookies, the product you are harvesting on went out of stock; move to a new in-stock product.

  • The in-bot harvester has been passing Shape better than the extension. Start with in-bot if you can. You can also run the extension at the same time; test what generates best for you.

FAQ

Why do my tasks say "Waiting for Cookies" or "Waiting for Cookies (Login)"?

You are not generating that type of cookie, or tasks are consuming cookies as fast as they arrive while getting blocked. Waiting for Cookies (Login) needs login cookies; Waiting for Cookies (Product) needs add-to-cart cookies. See the extension guide.

One task loops on Shape block while others sit on Waiting for Product. Is the account blocked?

No. Shape blocks are not account-related. That task likely needs to re-add customer information, which is Shape-protected; the others already had it. It is completing an extra step, nothing more.

Do I need login proxies?

Only if you log in from the Accounts tab, which is not recommended. Otherwise login uses the harvester proxy.

What does error 401 mean in my Target logs?

A Shape block.

What does "Product Not Supported" mean?

Hover over the status to see the reason. The message reads "Shipping not available for this product (Target $35+ restriction)".

Refract only checks out with free shipping on Target, and Target's free shipping needs a $35+ cart. So a product under $35 cannot check out on its own: cheap products like Needohs will always show this status by themselves.

The fix is Add Extra Product: enable it on your tasks and set a custom filler item, like a Lego set, to bring the cart over $35. The filler is cancelled right after checkout, so you only keep the product you wanted.

Set the filler item yourself rather than leaving it blank. Left blank, the bot picks a cheap item, which is the right behaviour when Add Extra Product is being used for cancel help but does not necessarily get you over $35.

What does "Cart in Use" mean?

The account's cart is in use by another task. Let the task retry on its own.

What does "review hold" mean?

Target is reviewing the order. Roughly a 50/50 chance it does not get cancelled.

Why do I get "product not found" when the product is in stock?

If a product is truly in stock and the bot or your extension browser shows product not found or unavailable, that is a proxy rate limit.

What does "Rate Limited (Order)" mean?

Target rate-limits checkouts to prevent backend spam. It is unrelated to your proxies or accounts; let the task retry. For the drop-time version of this, see the release guide's Rate Limit (High Demand) section.

What does "Max attempts reached" mean while harvesting login cookies?

You are likely Shape blocked. Rest and improve the setup rather than hammering.

Can the bot reset my Target account's password?

Not currently.

What proxies should I use on Target?

Residential on tasks, and especially on harvesters. Resis use data, but they have been passing Shape much better. Keep ISPs on the monitor.

Will the bot adjust quantity if the max allowed is lower than what I set?

Yes. If you request 4 and Target allows 2, the bot goes for 2.

Last updated

Was this helpful?