Limited drops sell out in seconds. Vajra is a Windows CLI bot that runs hundreds of checkout tasks in parallel against Asian e-commerce and ticketing sites, sold as a licensed product rather than a script.
Four services, one product
- The bot — Go, a Cobra command tree with a Bubble Tea terminal UI. Task orchestrator, proxy pool, encrypted config and logs, self-update.
- Auth backend — the enforcement boundary. Trades a licence key for a session token, binds it to hardware, and gates each site module. Every request is a signed envelope carrying a timestamp and a nonce, so replays and stale calls are refused.
- Webhook relay — a queued Discord notifier. Success posts are handed off and forgotten by the bot; the relay owns retries, backoff and the dead-letter queue.
- Marketing site — a static Next.js export with no backend of its own.
What was interesting
Failure classification. A bot that retries blindly gets its accounts banned. Errors are classified before anything reacts to them — a soft rate limit, a dead proxy and a real block all want different responses.
Fail-open versus fail-closed, on purpose. When the auth service is unreachable, the notification relay keeps working for a token it has already approved: a lost success message is worse than a lost check. The checkout bridge, which holds live session cookies, refuses everything instead. Both behaviours are pinned by tests so neither drifts into the other.
Not leaking the customer. Device telemetry deliberately never resolves the public IP, because the only way to get it was a call outside the proxy pool — which would have tied every run to the operator's real address.