Target Setup Guide
Target is the most complex site Refract supports. On top of the usual accounts, profiles, and proxies, Target requires cookies to pass Shape (its anti-bot system), which means running a cookie harvester alongside your tasks. This guide builds the setup step by step.
New to Target? Run the starter configuration below, exactly as written, before customizing anything. If you do not at least make an attempt to follow this guide, we will not be able to help you.
Your first Target setup
To reduce fingerprinting issues and avoid the common mistakes, every new user should start with exactly this. It is also the setup that has worked best for the people we have helped:
A maximum of 10 tasks, on 10 unique Target accounts, one task per account per product.
Your local PC, not a server or RDP. Servers significantly increase Shape blocks due to common device fingerprints.
2 cookie harvesters: one on Chrome, one on Brave. Use in-bot harvesters (they have been passing Shape better; set the Brave browser path on the second one), or extension instances.
No proxies on tasks or harvesters. Only use proxies on the monitor, with at least 1 proxy per monitor input when running multi-SKU.
Multi-SKU on.
Experiment with task and monitor delays. Some users run as low as 1000, some as high as 4000; find what works for your machine.
Once this configuration is running successfully, you can experiment with different setups.
The build order
You will do six things, in this order. Steps 1-2 are the same as every other site:
Add your accounts and group them. Do not log them in from the Accounts tab.
Create your profiles, one unique profile per task.
Create a Target task group and set the monitor input (see Monitor Setup below).
Create your tasks (see Task Creation below).
Start tasks and harvest login cookies, then keep ATC cookies running (see Log in your accounts below).
When you're ready to expand
Once the 10-task setup is running and hitting, you can scale up, with a hard ceiling:
Up to 30 accounts maximum, one task per account per product, running the in-bot harvester.
Everything stays on a local PC. This is still not a server setup.
Scale your harvester count to hold about 3 cookies per running task. At 30 tasks that is roughly 90 cookies banked, and remember the trade-off: the more cookies you generate, the higher your flag risk. Harvesting on residential proxies has been helping pass Shape at this scale.
Do not push past 30. Target is not a game of scale, and users who scale harder consistently hit less.
Do not expect 100% success, and do not overreact to blocks. Shape on a drop has an extremely low pass rate, for everyone. That is the nature of the site, not a broken setup. When troubleshooting, look at your device, browser, and proxies, never the accounts.
How Target is different
Two kinds of cookies: login cookies (to log accounts in) and add-to-cart cookies (to cart Shape-protected products). Both come from a harvester: the extension, the in-bot harvester, or both at once.
Tasks use the harvester proxy for add to cart and login. Whatever proxies your extension or in-bot harvester runs on are the proxies your tasks present to Shape.
Refract always checks out with the profile info in the bot. You do not need to add your shipping address or card to the Target account yourself, or with another tool. On task start, Refract makes sure the profile's info is on the account and set as the default for checkout.
Everything known about Shape is in the release guide. Opening a ticket will not get you more; if we knew more, it would be written there.
Prerequisites
Target accounts: one task per account per product. The same accounts can be run more than once across products or multi-SKU.
Unique profiles, one per task.
Proxies: ISPs on the monitor. Residential (resi) on tasks, and especially on harvesters. Yes, resis use data, but they have been passing Shape much better. On a small local setup (up to 2 harvesters), harvesting with no proxies works too; your home IP is residential.
A local PC. Mac is best for Shape, then local Windows. Avoid Windows servers for Target if at all possible.
The extension installed, or the in-bot harvester set up (or both):
Monitor Setup
The monitor input is the product's TCIN, the number from the product URL. A URL will not work. Use ISP proxies on the monitor.
Multi-SKU is preferred on Target. With Use Multi Input on, add one product per line, with an optional price cap:
The price cap must be a whole dollar amount. Cents are not supported. Write 120, not 119.99. Round up to the next whole dollar.
If you put cents in the price cap, the task never picks the product up. It looks like it is running fine, it just never activates.
You can run the same accounts more than once for Target, but multi-SKU beats duplicating task groups: every group you duplicate doubles the cookies you need, since each running task should have 3 cookies banked. In numbers: 10 tasks in 1 group need 30 cookies. Duplicate that group and you have 20 running tasks needing 60 cookies. A third group makes it 90. Multi-SKU covers the same products with the original 30, and the more cookies you generate, the higher the likelihood you get flagged and Shape blocked.
Task Group Settings

Use Multi Input
Preferred for multiple products
Formats above
Monitor Proxy List
Your ISP list
Monitor Delay
3500 (default)
Price Max
Leave blank
Max price of 1 item, before tax and shipping. Blank means no cap. Whole dollars only: round up, no cents
High Stock & Pre-Orders only
OFF
ON makes the bot only go for high-stock items (10+ in the stock count) and pre-orders. Leave off by default, including for a normal potential restock
Hype Product
ON for Shape-protected drops
Required for all high-demand drops (cards, consoles, and similar). To test if a product is protected, run a task without it; if blocked, it is protected
Loop Checkouts
OFF
Optional, at your own risk; may increase flags and cancels. With multi-SKU it loops the same product until OOS, then moves to the next
Task Creation

Required fields:
Profiles
Your Profile Group
One unique profile per task
Task Proxy List
Your residential list
Resis have been passing Shape much better. Leave blank for localhost (not recommended)
Accounts
Your Account Group
Every task needs an account
Retry Delay
3500 (recommended)
Experimenting with lower delays is fine; defaults are the baseline
Task Qty
1
Tasks per profile. About 30 tasks total is the suggested max at this time; see How many tasks should you run?
Item Quantity
1
A ceiling, not an exact number: the task goes for the max it can get, up to what you set. See How Item Quantity works
Optional fields:
Match account to profiles (by email)
Pairs accounts to profiles with the same email
In-Store Pickup
Required for in-store-only products
Use Target Circle Balance
Uses rewards at checkout if available
Login with OTP
Logs in with a code sent to the account email; may pass login antibot better. Pair it with IMAP or enter codes in the pop-up
Add Extra Product
Needed for items under $35: Refract only checks out with free shipping, and Target's free shipping needs a $35+ cart (tasks show "Product Not Supported" without it). Adds a filler product (set a custom item, like a Lego set) and cancels JUST THE LEGO after checkout. Set the item yourself; left blank the bot picks a cheap one that may not clear $35. Also designed to help with Item Demand cancels; how much that helps is unknown
Log in your accounts
Do not log in from the Accounts tab. Target accounts log in with cookies:
Harvest login cookies
Follow the extension guide to harvest login cookies on the Target account page. Tasks log in and move on as cookies arrive.
Optionally use Login with OTP (with IMAP) for the lowest-security login path.
Sessions logged in via the extension last days or weeks. Logging in from the Accounts tab is not recommended and produces much shorter sessions.
Cookies: the rules that matter
There is no one-size-fits-all fix for Shape blocks. Shape scores your whole setup (device, browser, proxies, cookie volume, and the product's security level) together. What fixes one user's blocks does nothing for another's.
Target: about 3 cookies per running task banked. Not a giant pile. Generating far more raises your own flag risk.
Quality beats quantity. A small batch of high-quality cookies carts; a huge stash of flagged ones does not. If you are not carting with 3 cookies per task, more bad cookies will not fix it. Improve the setup (device, browser, proxies) instead.
Harvest on any in-stock product. It does not matter what product you harvest on, as long as it is in stock and available for shipping. If harvesting suddenly stops producing cookies, the product you are harvesting on went out of stock; move to a new in-stock product.
The in-bot harvester has been passing Shape better than the extension. Start with in-bot if you can. You can also run the extension at the same time; test what generates best for you.
FAQ
Why do my tasks say "Waiting for Cookies" or "Waiting for Cookies (Login)"?
You are not generating that type of cookie, or tasks are consuming cookies as fast as they arrive while getting blocked. Waiting for Cookies (Login) needs login cookies; Waiting for Cookies (Product) needs add-to-cart cookies. See the extension guide.
One task loops on Shape block while others sit on Waiting for Product. Is the account blocked?
No. Shape blocks are not account-related. That task likely needs to re-add customer information, which is Shape-protected; the others already had it. It is completing an extra step, nothing more.
Do I need login proxies?
Only if you log in from the Accounts tab, which is not recommended. Otherwise login uses the harvester proxy.
What does "Product Not Supported" mean?
Hover over the status to see the reason. The message reads "Shipping not available for this product (Target $35+ restriction)".
Refract only checks out with free shipping on Target, and Target's free shipping needs a $35+ cart. So a product under $35 cannot check out on its own: cheap products like Needohs will always show this status by themselves.
The fix is Add Extra Product: enable it on your tasks and set a custom filler item, like a Lego set, to bring the cart over $35. The filler is cancelled right after checkout, so you only keep the product you wanted.
Set the filler item yourself rather than leaving it blank. Left blank, the bot picks a cheap item, which is the right behaviour when Add Extra Product is being used for cancel help but does not necessarily get you over $35.
What does "Cart in Use" mean?
The account's cart is in use by another task. Let the task retry on its own.
What does "review hold" mean?
Target is reviewing the order. Roughly a 50/50 chance it does not get cancelled.
Why do I get "product not found" when the product is in stock?
If a product is truly in stock and the bot or your extension browser shows product not found or unavailable, that is a proxy rate limit.
What does "Rate Limited (Order)" mean?
Target rate-limits checkouts to prevent backend spam. It is unrelated to your proxies or accounts; let the task retry. For the drop-time version of this, see the release guide's Rate Limit (High Demand) section.
What does "Max attempts reached" mean while harvesting login cookies?
You are likely Shape blocked. Rest and improve the setup rather than hammering.
Last updated
Was this helpful?