Skip to main content
What happened?

What should I do?

Can I try again?

Technical details
A

Automation Station

First-run

Local cloud setup

Data folder + admin for local cloud. On Vercel use env vars.

Password is for this site only — not your Whop password. New customers: (1) Create account with email + password, (2) Buy on Whop with the same email, (3) Sign in here.

A

Automation Station

Signed in

— Windows apps online 0 jobs queued 0 jobs running 0 jobs done 0 jobs failed
?
These are jobs, not coupons. Queued means work waiting for CVS Cloud Listener on your PC.
Setup: —

Setup

Getting you ready

We check what is actually configured — not a generic checklist.

    Details
    
            
    ✉️

    Workbench

    Coupons

    Sync your CVS emails, then activate coupons onto your ExtraCare cards.

    Sync mail

    Provider: …

    Scheduler: off · Settings

    Manual sync · pick messages to parse

    HTML test parse

    List:

    No coupons in this view. Set up email in Settings, make sure the Windows app is online, then Sync unread mail. Filters above can hide history (On Card / Used / Problems). New here? Open the First hour checklist.

    Quick activate (advanced — paste a coupon link)

    Start activation

    Most members never need this — Sync finds links automatically.

    ✨

    Workbench

    New Accounts

    Generate ExtraCare accounts with your dedicated Windows app

    Run

    Generate accounts

    ?
    Real browser opens CloakBrowser on your PC and creates a real CVS account. Dry run never touches CVS and proves your settings save correctly.
    ?
    This must be a catch-all domain. New Accounts invents addresses like Ava.Graham9728@yourdomain.xyz — those are not real mailboxes. Catch-all forwards every @yourdomain.xyz message to one inbox (usually Gmail) so CVS mail and coupons arrive.

    Buy a cheap .xyz on Namecheap (about $2 the first year). Do not buy Private Email or hosting. Full Namecheap steps: Catch-all domain guide.

    One domain, or several separated by commas (round-robin in a batch).
    ?
    US ZIP used on the CVS create-account form for each new ExtraCare account.
    ?
    How many accounts to create per click (1–50). Each account is a separate job; the listener runs them one at a time. Not the same as Max attempts (retries). Start with 1–3 until a batch succeeds end-to-end.
    ?
    Minutes to wait between successive accounts in a multi-account batch. 0 (default) = no intentional gap — jobs still run one at a time. Example: batch 10 with delay 5 → account 2 starts ~5 min after enqueue, account 3 ~10 min, etc. Saved with Account settings.
    ?
    Structured failure phases for calibration. Only available for the authorized operator account.
    ?
    CloakBrowser (recommended) is stealth Chromium on your PC. Without a key you get Chromium 146. A free license from cloakbrowser.dev/free unlocks the preinstalled Chromium 150 build.

    Patchright is an optional Playwright-compatible engine using Google Chrome installed on this PC. CloakBrowser remains the recommended default. Missing Chrome or Patchright causes the job to stop; it will not switch engines automatically.

    Automation

    Account settings

    ?
    Optional bandwidth saver for New Accounts browser runs. It blocks heavy resource types (images, CSS, and similar) to cut proxy data. Higher levels use less bandwidth but can break the CVS page. Leave off unless you need deeper cuts. Tracker blocking is a separate checkbox. Coupon Parser has its own Data saver pulldown under Coupon activation.
    ?
    Recommended on. Blocks third-party hosts that often dominate residential proxy bills (Adobe, LaunchDarkly, AppDynamics, Tealium, OneTrust, Quantum Metric, Medallia, mPulse, techlab CDN, …) — not www.cvs.com. Signup should still work; turn off only if a form acts broken. Independent of Data saver P1–P5.
    ?
    How CloakBrowser first opens CVS for signup.
    auto / lookup_first — go straight to the email look-up page (recommended; how live runs work).
    direct_then_warmup — opt-in: wipe session, open the CVS homepage, then look-up (not the default).
    direct_create — legacy name; still forced to look-up first so CVS does not bounce bare create URLs. Leave on auto unless calibrating.
    ?
    How many signup tries per account job (1–4). Fresh email + proxy rotate on retry. Not batch size. After 2 bot/network walls a job stops early on purpose — the job card shows why (e.g. “stopped early: bot wall”). Save settings after changing.
    ?
    Optional custom CloakBrowser profile folder on your PC. Leave blank for auto cloakbrowser-profiles/<your-user-id>/account-creation next to the listener.
    ?
    Password applied to every new CVS account this member creates. Leave blank when saving if you only want to keep an already-saved password.
    ?
    Where phone numbers / OTP come from for CVS signup. getatext rents numbers via API (usual). manual / webhook / none disable automatic rental.
    ?
    Secret API key for GetAText SMS rental. Required when SMS provider is getatext. Stored per account; leave blank on Save to keep an existing key.
    ?
    Leave blank = Chromium 146 (no key). Paste a free cb_… key from cloakbrowser.dev/free (GitHub sign-in) to use preinstalled Chromium 150 (recommended). The key only unlocks that build — nothing is downloaded. Any CloakBrowser key you already have also works. Type clear and Save to remove a saved key.
    ?
    GetAText service slug for CVS — keep cvs unless support says otherwise.
    ?
    Advanced: POST OTP events to your own endpoint. Leave empty. Unused for GetAText.
    ?
    Live New Account will not launch Cloak without a usable residential proxy. Home / ISP IP ExtraCare create fails after OTP. Coupon parser stays direct and does not use this pool.

    Hard residential is preferred (sticky residential / ISP-style exits). Datacenter and cheap mobile pools fail CVS network-address checks far more often. One proxy line per account attempt works best — the listener rotates and marks bad exits.

    WealthProxies is a solid provider (residential.wealthproxies.com). They often run ~50% Discord discounts — join their Discord for coupon codes. Format: host:port:user:pass or http://user:pass@host:port. Enable proxy, paste a pool, then Save. Coupon clip can still use its own optional proxy setting.
    Proxy cycle: save a list to track unique lines used.
    Catch-all domain on Namecheap (cheap .xyz)

    New Accounts creates a unique address on this domain for every ExtraCare signup. Set the domain as a catch-all so all of those addresses land in the Gmail you already use for coupon sync. You do not create each mailbox by hand.

    1. Buy a cheap .xyz

    1. Open Namecheap domain search.
    2. Search a short unused name and pick the .xyz result — not .com.
    3. Check the first-year price. Aim for about $2 (promo .xyz). Skip if it is $8+.
    4. Checkout. Decline add-ons: Private Email, hosting, website builder. Domain Privacy is fine if it is free or already included.

    2. Turn on free Email Forwarding

    1. Namecheap → Domain List → Manage next to the new domain.
    2. Open the Advanced DNS tab.
    3. Under Mail Settings, choose Email Forwarding and Save all changes. Namecheap sets the MX records for you.
    4. Leave Namecheap DNS (BasicDNS / PremiumDNS / FreeDNS). Do not point mail at Cloudflare or Google Workspace unless you already know how to set catch-all there.

    3. Add the catch-all

    1. Still on that domain, open the Domain tab and scroll to Redirect Email.
    2. Click Add catch all (not Add Forwarder).
    3. In Forward to, enter the Gmail inbox that runs your coupon script. Save with the checkmark.
    4. Wait about an hour for forwarding to finish setting up.
    5. Test from a different address than the Gmail you forward to (Namecheap drops same-address tests). Send mail to anything@yourdomain.xyz and confirm it appears in that Gmail.

    Then type only the domain here (example: yourname.xyz), not a full email. Several domains: comma-separated; a batch walks them in order.

    Schedule

    Scheduled refill

    Type how many successful ExtraCare accounts to make each day (your Settings timezone) on the same coupon-parser schedule (hourly / smart hours). 15 means 15 real ExtraCare numbers today — not attempts, not your existing wallet. Failed jobs are replaced until today’s number succeeds. Independent of the Start-N-accounts button. Uses the same execution mode, domain, ZIP, proxies, and SMS as Generate.

    ?
    When on, Fire scheduler now and the hourly/smart window also enqueue New Account jobs until this many ExtraCare numbers succeed today. Failures do not count and are replaced. Existing wallet cards do not count. Prefer hourly in Settings if you want more refill chances than smart (3×/day).
    ?
    How many ExtraCare accounts must succeed today. Type 15 for 15 real cards today. Yesterday’s work does not count. Failed attempts do not count; the next fire (or a finished job) starts more until today’s number is met. Each fire caps at 50.
    ?
    Independent of Generate → Batch delay. Minutes between successive scheduled accounts in one fire. 0 = no extra gap.
    ?
    Independent of Generate → Data saver. Leave off unless scheduled runs need a tighter proxy budget.
    ?
    Independent of Generate → Entry strategy. Same look-up options; auto is recommended.

    Scheduled refill off. Set a completed-accounts target, then enable.

    Manual coupon on card

    Add coupon without email parser

    Search one ExtraCare account, pick a value chip, add. Built for large libraries (1k+ accounts) — we never render every card on this page.

    Load accounts to search…

    —
    —
    ExtraCare: —
    —
    Value on card
    No saved ExtraCare accounts yet Import or finish a live generation with a real ExtraCare number, then search above.

    Recent account-generation jobs

    Job history (including failed/stub). Only successful live runs with a real ExtraCare number are saved for wallet / manual coupons above.

    No account jobs yet Start a batch with CVS Cloud Listener online. Results show the email, ExtraCare number, and mode.
    💳

    Results

    Wallet

    On-card coupons · ExtraCare barcodes · job activity

    Export uses durable ExtraCare accounts with embedded barcodes. On the phone wallet: use Export sync JSON (not per-card ↗) to bring usedIds back; import that JSON here. Per-card ↗ shares a coupon PNG. Passwords are never included.

    Wallet value (Ready + On Card)

    ?
    Dollar total of Ready and On Card coupons in this wallet view. Percent-off coupons count toward Coupons but not the dollar total. Expired coupons drop off at 10:00 PM in your Settings timezone.

    $0

    Coupons
    0
    Ready
    0
    On Card
    0
    Accounts seen in jobs
    0
    Accounts with barcodes
    0

    My Wallet · merged on-card

    Official CVS-style cards · mobile-safe layout · ↗ share image · barcode when available.

    No wallet coupons yet — activate Ready coupons, add a manual coupon to a saved account, or import accounts in Settings → Data · import. New here? Open the First hour checklist.
    Status Type Id Mode / note When
    No jobs yet — enqueue from Coupons or New Accounts.
    🖥️

    Admin

    Listener fleet

    ?
    Each row is one member’s Windows app. Updates are signed; a bad download never runs. Setup.exe is still the recovery installer. Do not promote everyone onto a brand-new build in one step.

    Signed auto-update. Manual Setup.exe remains the recovery path. Never force every member onto a fresh build.

    Rollout

    ?
    Operator only = your PCs. Selected = allowlisted test listeners. Percent = a deterministic canary. Everyone is last. Pause stops offering new builds; it does not uninstall. Promote copies the selected signed build to Stable.
    ?
    Who may be offered the current signed Setup.exe. Widen the stage after a canary looks healthy. Members still download Setup.exe from this site if auto-update is paused.
    ?
    Used only in Percent canary. Cohort is hashed per member, not random each heartbeat. 0 = nobody extra; 100 = all in this stage.
    ?
    Stops offering a new signed build. Running listeners keep their current EXE. Setup.exe download on Settings still works.
    ?
    Marks the selected signed build as Stable. It does not push bytes to every PC immediately — listeners pick it up on their update channel.

    Member PC Current Target Channel Heartbeat Update Previous Error
    ?
    Queues a signed update command for the checked rows. The Windows app verifies signature and hash before replacing the EXE. Config next to the EXE is kept.
    ?
    Asks those PCs to return to the previous verified EXE. Rollback is bounded; it never runs an unsigned file. Use Setup.exe if a PC will not start.

    Membership

    Whop entitlement

    ?
    Local access vs the last signed Whop webhook. Reconcile asks Whop now; login does not. It will not invent membership. Revoked members have pending work cancelled.

    Local status vs last webhook. Reconcile compares Whop; it does not run on every login.

    Email Status Until Source Whop mem Last webhook Reconcile
    🚩

    Admin

    Release safety

    ?
    Flags and kill switches for new work. On for a kill switch blocks new jobs of that type; running jobs are not deleted. One failed HTTP request does not roll back a deploy. SLO is a rolling window, not a single failure.

    Feature flags, kill switches, and health gates. One failed request does not roll back a deploy.

    Running code

    ?
    Cloud version, git SHA, data schema, and the listener build this site expects. Health/SLO use recent jobs and HTTP 5xx — not a promise of uptime. Refresh reloads flags without deploying.

    Cloud version, git SHA, schema, expected listener.

    Health gate: —

    Flags & kill switches

    ?
    A flag turns a feature on. A kill switch blocks new jobs (parser, activation, New Accounts, scheduled refill, Gmail, marketplace). Toggle does not wipe wallet data. Promote widens a canary; it is not a Contabo deploy.
    Key Kind On Scope % Expires

    Product analytics

    Setup funnel & feature health

    ?
    First-party counts of setup steps and feature use. No coupon text, email bodies, OTPs, passwords, or Gmail URLs. Refresh loads aggregates; nothing is sent to a third-party SDK.

    First-party aggregate counts only. No coupon contents, email bodies, OTPs, or credentials.

    Refresh to load the privacy-safe setup funnel.

    Aggregate feature and error metrics
    
              
    ⚙️

    System

    Settings & Windows app

    Email, coupons, preferences, and the Windows app that performs browser work

    Windows app Email & coupons General Data Diagnostics Alerts Sign-in & devices Privacy Support
    First hour checklist
    1. Create account with the email you will use on Whop and a password for this site (min 8). This is not your Whop password. Then buy on Whop with the same email, then Sign in here.
    2. Windows app → Download installer → run CVS-Cloud-Listener-Setup.exe.
    3. Download config → save as listener.config.json beside CVS Cloud Listener.exe. Health should show the Windows app online.
    4. General → pick your timezone (coupons expire 10:00 PM in it) → Save.
    5. Have existing ExtraCare accounts? Data · import them before a large parse. Auto-unsubscribe stays optional and off.
    6. Open the Gmail setup guide and deploy the coupon script in Google (not from this site).
    7. Email parsing → Provider = Gmail (Google Apps Script) → paste URL + ?key=YOUR_SECRET → Save email settings.
    8. Before real work, switch coupon activation and New Accounts from Dry run (stub) to Real browser (live).
    9. New Accounts: set a catch-all email domain, ZIP, ExtraCare password, GetAText key, and enable residential proxies — then Save.
    10. Coupons → Sync unread mail, then Activate all ready coupons.
    11. Optional: deploy the verify script and enable Email preference confirm.
    12. Optional: Scheduler (in General) → smart hours such as 7,12,18. The coupon-parser scheduler only fires while this site is open in a browser — the EXE is not a cron.

    Windows app

    Your browser automation app

    One tray app per member. This background app is named CVS Cloud Listener in files and technical details. Download the Setup installer (CVS-Cloud-Listener-Setup.exe) — same for everyone (full tray + CloakBrowser; no tokens baked in). After install, your secrets go only in listener.config.json (Download config here, or tray Settings). Re-run a newer Setup.exe to upgrade in place.

    Config file location (required): listener.config.json must live in the same folder as CVS Cloud Listener.exe (the install folder after Setup — not Desktop alone, not Downloads, not inside the Setup.exe). Wrong folder = listener offline / “needs setup.” Tray Settings also writes that same file next to the EXE.
    ?
    Stable = signed production EXE. Beta = signed test builds when a canary is open. Pinned stays on the EXE this PC already has. Auto-update never runs an unverified file. Setup.exe is the recovery installer.

    Auto-update never runs an unverified download. Setup.exe remains the recovery installer.

    Listener update required.
    1. Click Download Installer below → run the new CVS-Cloud-Listener-Setup.exe (upgrades in place).
    2. Quit the old tray icon first if prompted (right-click → Quit).
    3. Keep listener.config.json in the same folder as the EXE (token + cloud URL) — upgrades do not wipe it.
    4. Start CVS Cloud Listener and wait for the health bar to show online. See SETUP.txt in the install folder.

    Where to put your data (listener)

    WhatWhere it goes
    Config file (required) Exact name: listener.config.json. Exact place: same folder as CVS Cloud Listener.exe (after Setup: usually under your Programs / install directory). Use Download config below and save there, or paste token in tray Settings (saves to that path).
    LISTENER_TOKEN Any of these (all write/use the same field in that file): Download config (pre-filled), or tray Settings → Listener token, or edit LISTENER_TOKEN by hand.
    CLOUD_BASE_URL Site you log into (e.g. https://parsecoupons.com) — in Download config, tray Settings, or the JSON next to the EXE.
    LISTENER_NAME Optional label for this PC (e.g. my-pc). Set here when generating Download config, or in tray Settings.
    Do not Do not leave the config only in Downloads/Desktop unless the EXE is there too. Do not put tokens inside Setup.exe — installer is generic; only the local JSON (same folder as the EXE) holds secrets.
    ?
    A label so you can tell PCs apart in the health strip, e.g. office-pc. Used when you Download config. Your listener token is one active token for the member account, not one token per PC.
    Advanced Windows app options
    ?
    How often the tray asks the site for new jobs. 5 seconds is fine.
    Job types this PC can run
    ?
    Leave all three on unless you have a second PC sharing the work: mail sync (email_parser), new accounts (account_generation), coupon activation (coupon_activation). Preference confirm is included automatically.
    Download installer
    ?
    Downloads CVS-Cloud-Listener-Setup.exe. Run it on the Windows PC that will do the browser work. The installer is the same for every member — your token is not inside it.
    Download config
    ?
    Downloads a small JSON with your token and site URL. Save it as exactly listener.config.json in the same folder as CVS Cloud Listener.exe.
    ?
    Makes a new listener token and stops the old one everywhere this account is used. After rotating, download the config again (or paste the new token in the tray's Settings).
    Windows app authorization
    ?
    This token links your PCs to this member account. There is one active token for the account — rotating it invalidates the previous token wherever it is used. Download config includes it, so most members never copy it by hand.
    (sign in)

    After Download config, save the file as exactly listener.config.json in the same folder as CVS Cloud Listener.exe (not a different folder).

    ?
    If this says your listener is out of date: Download installer again and run it over the old install. Your listener.config.json stays put.

    Setup templates

    Gmail Apps Script & Windows app sample

    Generic templates only — no member emails or tokens baked in. You add your secret key in Google, then paste the Web App URL into Email parsing below.

    Download: Gmail coupon script
    ?
    This file turns a free Google Apps Script into a feed of your CVS coupon emails. Paste it into Google, add your secret key, and deploy. Full steps: Gmail setup guide.
    Download: Email verification script
    ?
    Finds CVS Action Required: Confirm Your Email Preferences mail so Automation Station can confirm for you. Optional. Use its own Google project.
    Download: Gmail skip filters (XML)
    ?
    Subject skip is product $5 off for (not Miss You). Body skip is off your $ / your $ ($3 off your $12 purchase). Not when you spend (that footer is on entire-purchase keepers). Keepers: $N Coupon! entire purchase, $5 Off - Just Because We Miss You, Birthday.
    1. Download the XML (this button). Delete every older CVS skip filter first.
    2. In Gmail: Settings (gear) → See all settings → Filters and Blocked Addresses → Import filters.
    3. Pick the downloaded cvs-gmail-skip-filters.xml.
    4. Check Apply new filters to existing email.
    5. Click Create filter (or Create filters).
    6. Old labels stay. Search label:cvs-skip ("your entire purchase" OR subject:Birthday OR subject:"Miss You" OR subject:"off =") and remove cvs-skip from those.
    Re-import when we update this file. Full steps: Gmail skip-filter import.
    Listener config example Listener: where to put data
    Set up Gmail in Google (guided steps)

    Sync reads Gmail through a script you own. Automation Station never sees your Gmail password. Sign into Google with the Gmail that receives CVS mail.

    1. Download cvs-gmail-coupon-feed.gs above (and later cvs-email-verification.gs if you want preference confirm).
    2. Invent a long secret (40+ characters). You will use it twice: in Google and in the URL ?key=YOUR_SECRET.
    3. Go to script.google.com → New project. Open Code.gs, delete the sample, paste the entire downloaded file. Save.
    4. Project Settings (gear) → Script properties → Add script property: coupon script name GMAIL_COUPON_SCRIPT_KEY; verify script (its own project) name CVS_VERIFIER_SCRIPT_KEY. Value = your secret. Save.
    5. Deploy → New deployment → Web app. Execute as Me. Who has access: Anyone. Deploy and authorize.
    6. Copy the Web app URL ending in /exec. Paste it in Email parsing: coupon URL into ep_gmail (Gmail coupon script URL); verify URL into ep_gmail_verify (optional). Always append ?key=YOUR_SECRET.
    7. Set Provider to Gmail (Google Apps Script) → Save email settings.
    8. Test in a browser tab: …/exec?key=YOUR_SECRET&action=status should return JSON, not list your mailbox. Then use Sync unread mail or Run preference confirm now.
    9. To update later: download the latest .gs, replace Code.gs, Deploy → Manage deployments → Edit → New version → Deploy. The URL stays the same; the key must still match.

    Common failures: 403 = ?key= does not match the Script property; no mail = wrong Google account or access left on Only myself; no jobs = Provider still Off or you forgot Save email settings. The keyed URL is a secret — do not share it. Do not put both scripts in one Google project.

    Import Gmail skip filters (product ExtraCare)

    Optional. The XML creates two filters (both label cvs-skip and archive). Gmail hasTheWord searches the body, not only the subject. Subject filter: product $N off for / % off / Weekly Ad. Body filter: off your $ / your $ ($3 off your $12 purchase, $2 off your $5 toothpaste), off any. Do not use when you spend — ExtraCare $N Coupon! entire-purchase keepers share a beauty-sale footer with that phrase. Both exclude Birthday, ExtraBucks, entire/next purchase, and $5 off =. Do not use Weekly Ad as a body word — it is in almost every CVS footer.

    1. Download cvs-gmail-skip-filters.xml from Setup templates above.
    2. If an older CVS skip filter exists (especially one that used off + or bare off for without keeper exclusions), delete it first. Gmail treats + as an operator and would archive almost every “off” subject — including $5 off = !!!.
    3. Gmail → Settings (gear) → See all settings → Filters and Blocked Addresses → Import filters.
    4. Pick the XML file.
    5. Check Apply new filters to existing email. so already-received product mail is archived too.
    6. Click Create filter.
    7. Re-import does not un-label keepers already in cvs-skip. Search label:cvs-skip ("your entire purchase" OR subject:Birthday OR subject:"gift is inside" OR subject:ExtraBucks OR subject:"Just Because We Miss You" OR subject:"Pharmacy Receipt" OR subject:"Popular Online Deal" OR subject:"off =") → select → Labels → uncheck cvs-skip → Move to Inbox if archived.

    Re-download and re-import when we add skip subjects (surveys from medallia.com, Take a Spin, Welcome Reward, etc.). Sign into the same Gmail the coupon script reads.

    Where to put your data (Gmail scripts)

    What you invent / getWhere to put it
    Secret key (any long random string) Google Apps Script → ⚙ Project Settings → Script properties → Add property:
    Coupon script: property name GMAIL_COUPON_SCRIPT_KEY, value = your secret
    Verify script: property name CVS_VERIFIER_SCRIPT_KEY, value = your secret
    Do not leave the default replace-me-with-a-secret in production.
    Script source code script.google.com → New project → open Code.gs → paste the full downloaded .gs file (replace any sample code).
    Web app URL (after Deploy) Deploy → New deployment → type Web app → Execute as: Me · Who has access: Anyone → Deploy → copy URL.
    Then in this site (Email parsing): paste
    https://script.google.com/macros/s/…/exec?key=YOUR_SECRET
    → Gmail coupon script URL or Gmail verify script URL.
    Gmail inbox used No field to fill — the script reads mail from the Google account that owns the Apps Script project (the one you signed in as when creating it).

    Provider must be set to gmail_apps_script in Email parsing, then click Save settings.

    Where to put your data (listener.config.json)

    JSON fieldWhat to put
    CLOUD_BASE_URL Site URL, e.g. https://parsecoupons.com (no trailing slash issues if present).
    LISTENER_TOKEN The lt_… token from the Listener box on this page (or use Download config).
    LISTENER_NAME Friendly name for this PC (e.g. office-pc).
    LISTENER_CAPABILITIES Comma list, usually email_parser,account_generation,coupon_activation.
    POLL_INTERVAL_SECONDS How often to poll jobs (e.g. 5).

    Easiest path: Download Installer → run Setup → Download config and save as listener.config.json in the same folder as CVS Cloud Listener.exe (or start tray and paste token in tray Settings, which writes that same file).

    Email parsing

    Mailbox / Apps Script

    Recommended: Gmail (Google Apps Script). Paste your deployed Web App URLs with ?key=YOUR_SECRET. Full steps: Gmail setup guide. IMAP fields are Zoho only.

    ?
    Gmail (Google Apps Script) reads a Gmail inbox through the scripts you deploy (recommended). Zoho (IMAP) uses host and app password below. Off = no mail sync.
    ?
    How many recent CVS messages each sync looks at. Default 200. $3 ExtraBucks stay above the $2 skip floor.
    ?
    Paste the coupon Web App /exec URL plus ?key=YOUR_SECRET. The key must match Script property GMAIL_COUPON_SCRIPT_KEY. Deploy as Execute as Me, access Anyone. Full steps: Gmail setup guide.

    Required for Sync. Ends with ?key=YOUR_SECRET.

    Gmail script update required.
    1. Download the latest script from Settings → Setup templates.
    2. In Google, replace Code.gs, then Deploy → Manage deployments → Edit → New version → Deploy.
    3. Confirm the Script property still matches the ?key= here, then Save email settings.

    ?
    Own Google project. Script property CVS_VERIFIER_SCRIPT_KEY. Deploy Execute as Me, access Anyone, then ?key=YOUR_SECRET. If empty, preference jobs fall back to the coupon script. Full steps: Gmail setup guide.

    Optional. For CVS Action Required: Confirm Your Email Preferences — also configure Settings → Email preference confirm.

    ?
    After a message is parsed successfully, it is marked read so later syncs skip it. This does not delete mail. Turn off while testing so you can re-sync the same message.
    Advanced (IMAP, subject filter, AI fallback)
    ?
    Only for Zoho (IMAP). Leave empty for Gmail.
    ?
    Usually 993 for Zoho IMAP.
    ?
    Your Zoho mailbox address. Leave empty for Gmail.
    ?
    Use a Zoho app password, not your login password. Leave empty for Gmail.
    ?
    Only parse CVS emails whose subject contains this text. Leave empty to read all CVS senders.
    ?
    Optional backup when normal rules find no coupons. Most members never need this.
    ?
    Your own Gemini API key for the optional fallback parser. Leave empty unless you use AI fallback.

    Coupon activation

    Activation defaults

    ?
    Coupons at or below this $ amount are skipped, not activated. Default skips $1–$2 so jobs are not wasted on low value.

    Default: $2.

    ?
    Dry run simulates activation — nothing leaves the site. Real browser opens CloakBrowser through your CVS Cloud Listener and actually clicks Send to Card.
    ?
    Off by default — clips use this PC's IP, same as clicking Send-to-card yourself. On = New Account residential proxy (often makes ExtraCare reject the clip). Does not change New Account generation. Same switch as the lamp on the Coupons page.
    ?
    Same P1–P5 resource-type blocking as New Account, but only for Coupon Parser when the clip is actually going through a proxy. Direct (no-proxy) clips stay a full page load. Leave off unless you need to cut proxy GB. Tracker blocking is the checkbox below.

    Only used when coupon clip uses a New Account proxy.

    ?
    Off unless you need to cut proxy GB. Blocks Adobe / ads analytics — never PerimeterX or Akamai (those scripts must load or CVS treats the clip as a bot). Ignored on a direct (no-proxy) clip. Independent of Data saver P1–P5. Leave off for Send-to-card.
    ?
    When a sync finds Ready coupons, activation jobs start on their own. Off = sync only fills the work queue; you activate from Coupons. If CVS says the coupon wasn’t sent / the deal is unavailable, that clip is skipped (not retried forever). New Account proxy + Coupon data saver apply only when the clip is proxy-activated.
    ?
    When ON and activation is live: if a coupon email's recipient is not one of your saved ExtraCare accounts, the listener opens that email's unsubscribe link and sets Unsubscribe from all = Yes. Import accounts first. Off by default.

    Off by default (opt-in). When you turn it on and coupon execution is live, orphan coupon recipients open the email unsubscribe link, select Unsubscribe from all promotional emails = Yes, then Submit.

    Avoid mass unsubscribe: this runs for any coupon email_to that is not in your durable ExtraCare account list. Import accounts first (Shocked CVS / CVS Side Server Discord exports, or restore JSON) — see Settings → Data · import below — before enabling this and running a large coupon parse.

    Advanced browser options
    ?
    Defaults are correct for CVS Cloud Listener. Only change with support.
    ?
    Defaults are correct for CVS Cloud Listener. Only change with support.
    ?
    Defaults are correct for CVS Cloud Listener. Only change with support.

    General

    Preferences

    ?
    Coupons expire at 10:00 PM on their expiry date in this timezone. The scheduler's hours also use it. Pick the timezone you actually live in — not the server's.

    Coupons expire at 10:00 PM in this Settings timezone. Scheduler hours also use it.

    ?
    Appearance of this site only. System follows your OS. It does not change the Windows tray app.
    ?
    Browser toast when a job completes while this tab is open. Separate from Incident alerts below, which fire on lasting problems (listener offline, stalled queue), not every failure.

    Incident alerts

    ?
    Lasting problems only: listener offline, stalled queue, dead-letter spike, SMS/proxy exhaustion, Gmail script failures. Not every failed job. Quiet hours use your timezone; critical events still send.

    Listener offline, stalled queue, dead-letter spike, SMS/proxy exhaustion, Gmail script failures. Not every failed job. Quiet hours use your timezone; critical events still send.

    ?
    Master switch for this account. Off = no browser or webhook incident alerts. Job-complete toasts above are separate.
    ?
    Uses this browser’s notification permission. The site must be open (or recently used) to show them. Secrets are never put in the notification body.
    ?
    Hours are in your Settings timezone and may wrap midnight (e.g. 22→7). Warning/info alerts wait; critical alerts still send.
    ?
    0–23 in your timezone. Example: 22 means 10:00 PM.
    ?
    0–23 in your timezone. Example: 7 means 7:00 AM. If start is later than end, quiet wraps overnight.
    ?
    HTTPS only. Discord webhook URLs send a short message. Other URLs get a JSON POST. Leave blank for browser-only. The URL is stored with your settings; it is never shown in alert history.
    ?
    Optional Bearer token for generic webhooks. Discord does not use this field. Saved value is masked; leave blank to keep it. Type clear to wipe.
    ?
    Sends a harmless TEST alert on the channels you enabled. It does not open a real incident or pause jobs.
    ?
    Off = you click Sync yourself. Hourly = about once an hour. Smart (3×/day) = at the hours below. Your Windows app must be online to do the work.
    ?
    Same as the auto-activate toggle, but only for scheduled runs.
    Advanced schedule and retention
    ?
    Older job history is cleaned up after this many days. Wallet accounts and coupons are kept.
    ?
    The clock hours smart mode runs, in your timezone above. Example: 7,12,18 = 7 AM, noon, 6 PM.
    ?
    Cap for each scheduled run. Keeps surprise backlogs small.

    Gmail · re-engagement

    Action Required: Confirm Your Email Preferences

    CVS sends re-engagement mail asking members to confirm they still want offers. Automation Station can find those messages and open the confirm/reactivation link (click.web.cvs.com / cloud.em…Reactivation_Success_PageV2) so you don’t click by hand. Requires a Gmail Apps Script URL (verify script preferred; coupon script listPreferenceEmails works as fallback) and an online Windows app.

    ?
    CVS periodically emails Action Required: Confirm Your Email Preferences. When this is on, each scheduled run finds those emails and clicks Yes, I still want emails so CVS keeps sending offers. Already-confirmed addresses are skipped for about a month. Needs the Gmail verify script (or the coupon script as fallback) and an online Windows app (listener).
    ?
    How many preference emails one run processes (1–50, default 20).

    Script URL is under Settings → Email parsing → Gmail verify script URL (or coupon script with preference list action). Save email settings first if you just pasted a URL.

    SellAuth / mysellauth.com

    Sell CVS coupon share cards

    List by $ amount, deliver the same image as Wallet → Share, mark coupons used in AS when sold, and set SellAuth stock to 0 when sold or expired. Open the full guide for step-by-step setup.

    ?
    Optional. Lists coupon share images by $ amount; when one sells, the coupon is marked used here and stock is zeroed on SellAuth. Open the full guide before enabling. Expired coupons drop at 10:00 PM in your Settings timezone.
    Marketplace fields (advanced)

    Used to verify Dynamic Delivery X-Signature.

    Lets AS set stock to 0 on sold/expired (remove from SellAuth).

    SellAuth products by $ amount ($3–$8)

    For each dollar amount you sell, enter the SellAuth product ID and variant ID (from the product URL or API). Leave blank if you don’t sell that amount. Both IDs are required for stock=0 after sold/expired.

    Value Product ID Variant ID
    $3
    $4
    $5
    $6
    $7
    $8
    
                

    Proxies

    Proxy pool validate

    Proxy validate (advanced)

    Validates scheme/host shape only (no dial). Pool is under Account settings.

    
                

    Blacklist

    Email / domain block

    ?
    Block an email or an entire domain. Blocked addresses are hidden from the wallet and skipped by activation.
    ?
    Use for dead or sold-elsewhere accounts. Enter a full email or a domain such as example.com.

      Data

      Backup · import · barcodes · danger

      Import ExtraCare accounts before large coupon parses. Auto-unsubscribe (Coupon activation settings above) treats any coupon recipient missing from this library as an orphan and may opt them out of CVS promotional email. Prefer Discord import or restore from backup first; then parse coupons.

      ?
      Everything in your account library + coupon records as one JSON. Keep one before big changes.
      ?
      Your full ExtraCare library — email, ExtraCare number, birthday, phone, and passwords where stored. Treat this file like a password list.
      ?
      Creates barcode images for saved accounts that do not have one yet, in the background.
      Barcode calibrate (tec-it vs local)
      ?
      Reloads a backup JSON from this site. Does not delete existing accounts unless they conflict.
      ?
      If you bought or generated accounts from Shocked CVS / CVS Side Server, export the seller's Discord channel with Discord Chat Exporter (HTML) and drop it here.
      ?
      Deletes your accounts, coupons, and history from this site. Download a backup first. There is no undo.

      Discord import reads HTML from Discord Chat Exporter (Shocked CVS / CVS Side Server “Account Generated” embeds) into your durable ExtraCare list. That is how you load a legacy library so coupon emails match and are not treated as no-account. Export all accounts downloads your durable ExtraCare library as JSON (email, ExtraCare, password when stored, phone, birthday).

      Observability

      Diagnostics & job history

      ?
      Shows job types, error classes, and whether a retry is safe. Filters do not change saved data. Fixtures and timelines never include passwords, OTP, or proxy credentials.

      What is running, where it failed, and whether it is safe to retry. No passwords, OTP, or proxy credentials.

      Contracts

      ?
      Cloud, Windows app, and Gmail script schema versions. They are independent of the listener release version. A stale Gmail script shows a banner in Email settings, not here.

      Cloud / listener / Gmail schema versions (independent of the listener release).

      Queue

      ?
      Pause stops new claims for your account; jobs already running finish or wait for cancel. Dead-letter is exhausted retries — replay one at a time from the list. No fake ETAs.

      Queued, running, dead-letter, and pause controls. No fake ETAs.

      ?
      Your Windows app will not pick up new jobs until you Resume. It does not uninstall the app or wipe coupons.

      Alerts

      ?
      Lasting problems only (Gmail script, Windows app offline, credits, membership). History shows the latest state of each issue — started, still going, or cleared. Secrets are never listed.

      No issues right now

      Jobs (newest)

      Job timeline

        Support

        Create diagnostic bundle

        ?
        You preview the exact JSON before download. It is never uploaded by itself. It excludes passwords, OTP, cookies, session/Windows-app tokens, proxy credentials, and Gmail ?key= URLs.

        Builds a sanitized report with versions, connection health, setup checks, queue totals, recent status/error classes, and incidents. You preview the exact file before downloading. It never includes passwords, codes, cookies, session/Windows-app tokens, proxy credentials, or Gmail secret URLs, and it is never uploaded automatically.

        ?
        Builds the file locally in this browser session. Preview the exact contents, then download if you want to send it. Nothing is uploaded automatically.

        No bundle has been created yet. Create one to review its support ID and exact contents.

        Exact bundle contents
        
                  

        Account

        Sign-in & devices

        ?
        Optional authenticator app, one-time recovery codes, and passkeys on HTTPS. Your existing password still works. Rotating the Windows-app token is a different control under Windows app settings.

        Optional authenticator (TOTP), recovery codes, passkeys on HTTPS, and signed-in devices. Existing passwords keep working.

        Authenticator: off

        ?
        Uses an authenticator app (not SMS). The secret is shown only during setup. Recovery codes appear once — save them. Turning 2FA off asks for a recent password or code.

        
                    
        ?
        This site password only — not Whop. Minimum 8 characters. Changing it signs out other devices after a recent-auth check.
        ?
        Uses this device’s passkey (Windows Hello, phone, or security key). Needs HTTPS. Passwords still work. The private key never leaves the device.
        ?
        Ends every session except this browser. The Windows app token is separate — revoke that under Privacy if a PC is lost.
        ?
        Ends every web session including this one. You will need to sign in again. Does not uninstall the Windows app.

          Privacy Center

          Your data & access

          ?
          Download my data is a readable export without secrets. Download backup (Data section) is the restore file. History delete does not cancel running jobs. Account deletion has no undo.

          Download my data is a readable, credential-free export. Download backup above is the separate restore artifact.

          ?
          Readable export of what this site stores for you, without passwords, tokens, or Gmail keys. It cannot restore the account — use Download backup in Data for that.

          Loading the categories stored for your account…

          Delete selected finished history
          ?
          Removes stored history you check. It does not cancel queued or running jobs, and it does not delete ExtraCare accounts or wallet coupons.

          This does not cancel or delete queued/running work.

          Access revocation & permanent deletion

          ?
          Requires your password again. Revoke Windows app if a PC is lost. Permanent delete stops schedules, ends sessions, cancels queued work, then deletes or anonymizes member data. There is no undo.

          These actions require your password again. Revoking the Windows app stops its current config from connecting. Account deletion stops schedules, revokes sessions and the Windows app, cancels queued work, then deletes or anonymizes member data. There is no undo.

          Security check

          Enter your password again

          Required before changing or deleting private data.

          Private · this login only

          Amazon Vine Review Writer

          Uses CloakBrowser on the PC running your Windows app. If Amazon asks you to sign in, enter email, password, and the 2-factor code in that window — the task waits up to 10 minutes.

          Settings

          Newest Vine items stay in the list as skipped until they are this many days old.

          Exact ASINs or title keywords. Hidden from the queue (Show skipped ASINs to reveal). Generate, submit, and batch ignore them.

          Proficient · 45-60 WPM

          No Vine items yet.

          Settings · SellAuth

          Full setup: sell CVS coupons on mysellauth.com

          Goal: list coupons by $ amount, buyer gets the coupon image (same as Wallet → Share), sale marks coupon used in Automation Station, and sold/expired items leave SellAuth stock.

          A · What the buyer gets

          • Product page image = share PNG you upload (barcode + $ + ExtraCare)
          • After payment, Dynamic Delivery returns a direct image link plus ExtraCare + expiry text
          • Image art is identical to Wallet → Share

          B · Automation Station (this page)

          1. Enable marketplace.
          2. SellAuth shop webhook secret — SellAuth dashboard → Storefront → Configure → Miscellaneous (Regenerate if needed). Used for X-Signature HMAC.
          3. SellAuth API key — Account → Developers on dash.sellauth.com.
          4. Shop ID — your numeric shop id from the SellAuth API / dashboard URL.
          5. $3–$8 table — for each dollar amount you sell, enter SellAuth product ID and variant ID (both are needed for stock updates). Find them in the SellAuth product page URL/API.
          6. Save marketplace → Download share images (PNG).

          C · Create products on SellAuth (by $)

          1. One product or variant per face value. Name must include the dollar amount, e.g. $5 ExtraBucks, $10 ExtraBucks.
          2. Upload the matching PNG as the product image.
          3. Deliverables type: Dynamic (webhook).
          4. Paste this Dynamic Delivery URL on every product:
          https://YOUR-HOST/api/webhooks/sellauth-delivery

          D · When a buyer pays (automatic)

          1. SellAuth POSTs INVOICE.ITEM.DELIVER-DYNAMIC with X-Signature.
          2. AS picks an on-card share for that $ amount.
          3. AS marks the coupon used (sold / out of inventory here).
          4. Buyer delivery text includes a coupon image URL (open/save/show at CVS) + ExtraCare + expiry.
          5. AS sets that SellAuth variant stock to 0 (via API map) so it is removed from sale, and also zeros stock for any expired $ amounts.

          E · Expired coupons

          After every sale, AS re-checks 10:00 PM expiry in your Settings timezone and zeros SellAuth stock for those $ mappings. Click Sync expired → SellAuth stock 0 anytime (e.g. daily) to force a pass without a sale.

          F · Checklist

          • Products named with $5 / $10 / …
          • $3–$8 rows filled with product ID + variant ID for amounts you sell
          • Dynamic Delivery URL = field above (auto-filled)
          • Webhook secret matches SellAuth Miscellaneous secret
          • API key can update stock
          • Never put CVS passwords in SellAuth

          Docs: Dynamic Delivery · Update Stock · mysellauth.com

          Settings · Import

          Discord CVS account importer

          Export a channel/DM with Discord Chat Exporter as HTML, then drop the file here. Works with Shocked CVS and CVS Side Server “Account Generated” embeds (ExtraCare, email, password, phone, birthday).

          Drop HTML export(s) here or click to browse

          Multiple files OK · Chat Exporter HTML only · max ~25 MB each