Models & Research

OpenAI lets ChatGPT sign in to your accounts and keep the session

OpenAI switched on account sign-in for the ChatGPT Work cloud browser on August 25, so the agent can now get into a password-protected site and stay signed in for later tasks. Before that change the cloud browser couldn’t handle any page behind a login wall, as Tech Times reported. ZDNet says the option is limited to Pro and Plus accounts, while TFTC lists Business, Enterprise and Edu too, so the exact rollout isn’t settled in public reporting.

The flow puts a wall between the model and your password. When the agent reaches a login page, a separate review model checks the destination for phishing risk, then ChatGPT surfaces a form and you type the username, password and any two-factor code yourself. OpenAI says the model never sees those credentials, doesn’t store them, and doesn’t use them for training. A password manager can autofill into the same form.

What sticks around is the cookie. The cloud browser keeps the authenticated session on OpenAI’s own infrastructure rather than on your laptop, which is what lets the next task skip the login entirely.

The authentication will persist for future tasks until it expires, so you do not need to sign in each time.

OpenAI documentation, quoted by Notebookcheck

Access to each site is governed by three settings, though OpenAI labels the loosest of them as one you shouldn’t pick.

SettingBehaviour
Always askThe default. Every site needs your approval before the agent visits it.
Auto approveThe agent proceeds once the site clears an automated risk assessment.
Always allowNo approval prompt. OpenAI marks this one “not recommended”.
Cloud browser site permissions, as documented by MacStories, Notebookcheck and Tech Times.

Still, the stored sessions can be dropped. Clearing cookies under Settings, Cloud browser, Browser data forces the next task to ask for credentials again, which ZDNet confirmed on an eBay account after deleting the saved cookies.

It doesn’t work everywhere yet, which is the recurring problem with agents that are capable enough to matter. ZDNet’s Amazon test failed on the ChatGPT website, where Amazon blocked the cloud browser, and only the Windows app got through. Two runs succeeded there, but Amazon then blocked the next attempts as well.

MacStories hit a different wall, but the pattern held. John Voorhees found Safari on the Mac failed outright, while the iPhone managed simple logins and stalled on CAPTCHAs. A session he started on the phone then carried over to the Mac, so the persistence is clearly working as designed.

That persistence is where the security objection lands, and it isn’t about the password.

Once authentication succeeds, the AI agent is operating inside an authenticated session with whatever privileges and entitlements the user possesses. At that point, a threat actor may not need the password since attacking the session itself becomes the actual prize.

Morey Haber, chief security advisor, BeyondTrust, via ZDNet

TFTC makes the same point through a custodial exchange analogy: an exchange doesn’t need your seed phrase to move your bitcoin, and OpenAI doesn’t need your password to reach your accounts. Haber’s route in is prompt injection, where an attacker hijacks an AI session to capture data or perform unwanted actions. OpenAI has said publicly, in a line Tech Times quotes, that prompt injection is unlikely to ever be fully solved, much like scams and social engineering on the web.

The confirmation gate covers less than it sounds like. Tech Times notes that bookings, payments and other consequential actions pause for your review, but reading, summarising and drafting don’t. It reckons those ungated steps cover the majority of what a webhook-triggered task actually does.

Shane Barney, chief information security officer at Keeper Security, told ZDNet that people should check account settings regularly for sessions or connected access they no longer recognise, and not assume access ends when the task does. Watch what OpenAI publishes next on revoking persistent access, and whether the workspace tooling in its Admin plugin for ChatGPT Work reaches which sites an agent may authenticate against.

Get the daily rundown

One email each weekday with the AI news that matters, every claim linked to its primary source.

Free, one email each weekday, unsubscribe in one click. We never sell or share your address.

Leave a Reply

Your email address will not be published. Required fields are marked *