It works in the tab you are signed in to
Every read and every change is a request made from inside your own Vinted page, so the browser attaches your session to it exactly as it does when you click something yourself.
A Vinted bot, as the word is normally used, is software that signs in as you and works the site on its own. Cavri is a Chrome extension: it acts inside the Vinted tab you are already signed in to, on listings that are already yours, one queued job at a time.
The requests that change a listing are made from inside the Vinted page, carrying the session your own browser already has. No Cavri server holds your Vinted login, because nothing in Cavri is ever given it.
What follows is what the extension asks Chrome for, what happens between pressing a button and Vinted changing, and where Vinted's own rules sit in all of it.
Three Chrome permissions · one marketplace · your own signed-in session
Every read and every change is a request made from inside your own Vinted page, so the browser attaches your session to it exactly as it does when you click something yourself.
Tabs, alarms and storage, plus Vinted's ten national sites and your own Cavri workspace. Chrome reads that list out before you install anything, which makes it the one description of an extension its author does not write.
Jobs are taken one at a time, roughly a minute apart, with the gap varied rather than fixed, whether you queued the batch yourself or a rule did. What the rules may queue on their own has a ceiling on top of that: 20 actions a day to start with, anything from 1 to 500.
One action, in order, from the moment you ask for it. A rule you switched on enters at the same place a button does.
Close Chrome and the queue stops where it is, and there is nowhere else for it to run. One queued job is one action, and a rule you switched on may queue 20 of them a day to begin with, which is a number you set.
Chrome shows this before you install anything, and it is the whole of what the extension asks for.
| What Chrome lists | What it is for | What that covers |
|---|---|---|
| Tabs | Finding the Vinted tab you are already signed in to, handing it one job, and reading the answer that comes back. | It works in a tab you already have open, or opens one in the background rather than taking over the window you are using. A wardrobe scan gets a background tab of its own, and it is closed again when the scan finishes. |
| Alarms | A timer that goes off once a minute and asks your own Cavri account whether anything is queued. | That is the whole of what the alarm does. When the answer is nothing, which it usually is, the extension goes back to sleep without opening a thing. |
| Storage | Four things: the address of your Cavri workspace, your Cavri API key, what the extension is doing right now, and the short-lived token Vinted's own page hands out to show a request came from that page. | The queue itself lives in your Cavri account rather than here, which is why closing Chrome pauses a batch instead of losing it. Your Vinted password and the cookie you are signed in with are in neither. |
| Vinted's ten national sites | The only marketplace it touches. Each site is listed separately because a browser cannot be asked for Vinted as one thing. | vinted.co.uk, .fr, .de, .es, .it, .nl, .be, .pl, .cz and .lt. |
| Your own Cavri workspace | So the dashboard and the extension can pair in one click instead of you copying a key between them. | One origin, the one you signed up on. Nothing else on the web is in the list. |
That is the list, and it used to be one line longer. An earlier version asked for the permission that lets an extension read the headers on requests the browser makes, which Cavri used to pick up two values Vinted's own page turns out to hand over anyway. It went in version 1.9.0, and what the extension is able to do has matched what it actually does since.
Vinted's terms restrict automated access to the site. Read plainly, that covers every tool in this category, Cavri included. Any tool telling you it is exempt is telling you something it has no way to know.
What Cavri does about that is keep the footprint small. The account is yours and you signed into it yourself. The listings are ones you already own. Jobs go through about a minute apart rather than in a burst, whoever queued them, and what the rules queue on their own runs under a daily ceiling you set: 20 to begin with, and you can put it lower.
What it cannot do is promise you an outcome. The terms are Vinted's to interpret and enforcement is Vinted's to carry out, and no seller tool has any standing in either. Cavri is independent of Vinted and has no arrangement with them, and nobody selling software is in a position to tell you the risk is zero.
If that is not a trade you want to make, the manual half works with every rule switched off: the wardrobe, bulk edits inside Cavri, the offers list, the numbers. Nothing changes on Vinted until you press something.
No. It does not sign into Vinted, it has no account of its own, and it runs nothing on a server. It is a Chrome extension that acts inside the Vinted tab you are already signed in to, on your own listings, when a job you queued or a rule you switched on falls due.
No, and there is nowhere to type one. You sign into Vinted yourself, in your own browser, exactly as you would anyway. Your Cavri login is a separate thing and has nothing to do with your Vinted one.
One of them, and only as a fallback. Vinted publishes an identifier called anon_id in its own API responses and also sets it as a readable cookie. The extension takes it from the response, and reads the cookie only when a response leaves it out. The cookie that signs you in is a different one and is marked HttpOnly, which puts it beyond every script in the page, Cavri's included.
A read, every five minutes or so. Cavri checks whether anything has sold and whether any offers have come in, so a sale does not sit unnoticed and an offer does not expire overnight. It runs even with automation switched off, because it changes nothing, and reads do not count against your daily ceiling. Anything that changes a listing waits either for you or for a rule you turned on yourself.
The queue stops where it is and picks up when you open it again. Whatever had already run stays done. There is nowhere else for it to run, so a laptop that is asleep is a queue that is paused.
This is one part of it. There is a page listing every rule Cavri can run, with its default and its cap.
100 items free, no card. Relisting, the price curve and the offer rules all start switched off, so you can queue one job by hand and watch it go through before you decide about the rest.