Profiles Setup
This guide covers how to configure the three profile systems in FingerBot: Email Monitoring Accounts, Guest Profiles, and Account Profiles. All three are managed from the Profiles tab in Settings. If you are only using the Target module, you can ignore Guest and Account Profiles.
Where to Find These Settings
Open FingerBot → click Settings → navigate to the Profiles tab. Inside you'll find four sub-tabs:
- Email Monitoring — IMAP inboxes for 2FA and order confirmation capture
- Guest Profiles — Shipping, billing, and payment details for guest checkouts
- Account Profiles — Retailer account settings/credentials
- Proxies — Proxy configurations Each of the first three sub-tabs has an Import button for bulk-adding entries from a TXT/CSV/JSON file — see Bulk Import.
Beginner Mistakes to Avoid
- Refresh proxy lists before known drops.
- Currently, only email-based 2FA (inbox OTP codes) are implemented. SMS-based 2FA is handled separately via macOS SMS forwarding (coming soon).
- Credentials are stored locally and encrypted in the app database. Do not use on shared machines. No sensitive information is ever sent to the cloud.
- Deleting an Account Profile is permanent with no undo.
- The Retailer dropdown is a fixed list (Macy's, Walmart, Amazon, Target, Sam’s Club, Amazon). Retailers without account-mode checkout support (e.g. Pokemon Center) do not appear here.
Quick Reference
| Feature | Email Monitoring | Guest Profiles | Account Profiles |
|---|---|---|---|
| Used by | Target, Walmart, Sam’s Club | PKC, Menards | Macy's, Walmart, Target, Sam’s Club, Amazon |
| Requires login? | No | No | Yes |
| Stores payment info? | No | Yes | No |
| 2FA support? | Yes | N/A | Yes |
Bulk Import
All three profile systems can be populated in bulk from a TXT, CSV, or JSON file. Each sub-tab (Email Monitoring, Guest Profiles, Account Profiles) has an Import button below its list.
Import Flow
- Click Import in the sub-tab you want to fill.
- Select the file to import.
- Review the preview table: every row has a checkbox, and invalid rows are locked with the reason shown in red. Fix bad data in place — double-click any cell (email, password, retailer, monitor link, …) and the row re-validates as you type; secrets stay masked unless you type over them.
- Click Import. Valid rows are saved; duplicates are skipped and anything that failed is reported in the summary.
Passwords, CVVs, and card numbers are masked in the preview — full values are never displayed.
TXT — one email:password per line
Supported for Email Monitoring and Account Profiles only (Guest Profiles must use CSV or JSON). Blank lines and lines starting with # are ignored.
text alice@gmail.com:my-app-password bob@outlook.com:another-password
- Email Monitoring: the monitor name defaults to the email address; IMAP server/port are auto-detected from the domain.
- Account Profiles: TXT files have no header, so pick the retailer with the Default retailer dropdown in the import dialog.
CSV — header row required
Column names are case-insensitive and tolerate spaces/dashes (Email Address and email-address both work). Unknown columns are ignored.
Email Monitoring columns
| Column | Required | Notes |
|---|---|---|
name | Yes | friendly monitor name |
email | Yes | full inbox address |
password | Yes | app password |
imap_server, imap_port | No | auto-detected from the email domain when omitted |
Account Profiles columns
| Column | Required | Notes |
|---|---|---|
retailer | Yes | amazon, macys, samsclub, target, or walmart |
email | Yes* | *Target may omit it when a monitor is linked — the monitor's address is used |
password | No* | *required for Amazon and Macy's; ignored for OTP-only retailers (Walmart, Target, Sam's Club) |
nickname | No | display name |
cvv | No | 1–4 digits; only honored for Walmart, Target, Sam's Club |
monitor | No | name or email of an existing Email Monitor (linkage) |
use_store_card | No | true/false; Macy's only |
Guest Profiles columns
| Column | Required | Notes |
|---|---|---|
profile_name | Yes | internal name |
email | No | used at checkout |
first_name, last_name, address1, city, state, zip_code, phone_number | Yes | state must be a two-letter code (e.g. CA) |
cardholder_name | Yes | name on the card; never inferred from shipping |
card_number, expire_month, expire_year, cvv | Yes | digits only; month 01–12, year YYYY, card ≤ 16 digits, CVV ≤ 4 digits |
address2 | No | |
billing_first_name … billing_zip_code | No | when omitted, billing is copied from shipping; provide any billing column to override |
is_po_box | No | true/false |
Card columns are imported as shared payments, not profile fields: identical cards across rows collapse into one payment that each profile links to. Manage them under Settings → Payments.
JSON — list of objects
Uses the same field names as the CSV columns. Either a bare list or an object wrapping the mode key:
{
"monitors": [
{
"name": "Personal Gmail",
"email": "alice@gmail.com",
"password": "app-password"
}
]
}
Use monitors, accounts, or profiles as the wrapping key to match the sub-tab.
Validation & Duplicates
- Every row must pass the same rules as the manual forms before it can be imported; the preview shows the exact reason otherwise.
- A
monitorlink must reference a monitor that already exists — import monitors before accounts that link to them. If the name matches multiple monitors, the row is rejected with the matching ids listed — use the monitor's id or exact email instead. - Invalid rows can be corrected directly in the table (double-click a cell); rows that stay invalid are simply skipped.
- Duplicate entries are skipped and reported, never overwritten: monitors by email, accounts by retailer + email, profiles by profile name.
- Sam's Club accounts always import with email-OTP auth (password auth is not yet supported).