AI NewsWords 1504Read time4 min

OpenAI Adds Secure Website Sign-Ins to ChatGPT Work

ChatGPT Work can now authenticate on websites through a secure form and continue delegated browser tasks without exposing passwords to the model.

OpenAI has added authenticated website access to ChatGPT Work’s cloud browser, removing a restriction that previously confined the remote agent to public pages. Users can now sign in when a delegated task reaches a supported login page, after which ChatGPT can continue working inside the authenticated session.

The consequential detail is how credentials are handled. Users enter their username, password, and any two-factor authentication code through a secure sign-in form. OpenAI says those credentials go directly to the remote browser: they are not visible to the model and are not stored by ChatGPT.

This expands the cloud browser from a research and public-form tool into an agent capable of interacting with personal and business accounts. OpenAI’s examples include checking utility plans, finding government appointments, saving apartment listings, reconciling invoices, and updating accounting records.

1. ChatGPT Work Can Now Operate Behind Login Screens

ChatGPT Work’s cloud browser runs on a separate computer in OpenAI’s cloud infrastructure. It can read pages, click controls, enter information, and carry out multi-step tasks on supported websites. The user starts the task from Work on the ChatGPT website or mobile app; there is no separate cloud-browser mode to select.

When a website requires authentication, the task pauses. ChatGPT presents the user with a secure sign-in flow rather than asking for credentials in the conversation. Once the user completes authentication, ChatGPT resumes the original task inside the resulting account session.

This changes the practical scope of delegated browsing. Public access was sufficient for comparing flights, checking product availability, or collecting information, but many administrative workflows depend on account-specific data and authenticated forms. Insurance portals, utility accounts, government scheduling systems, vendor dashboards, accounting services, and property platforms commonly place the useful part of the workflow behind a login screen.

OpenAI’s announcement illustrates that broader scope with tasks such as checking insurance reimbursement costs, preparing vehicle-registration paperwork, booking an in-network doctor, submitting medical reimbursement forms, scheduling package pickups, and moving invoices from email into accounting software. Whether any individual task succeeds still depends on the website, the user’s permissions, and the actions required.

The cloud browser can continue running after the user closes ChatGPT or turns off the device. It pauses again when it needs information, authentication, or approval, allowing a task started on mobile to proceed on the remote computer rather than on the phone itself.

2. Credentials Are Isolated From the AI Model

The secure form is the central security boundary in the new design. OpenAI states that usernames and passwords entered there are sent directly to the remote browser and are not shown to the model. ChatGPT also does not store those credentials.

The distinction is narrower than saying ChatGPT has no access to the account. After authentication, the agent can use the signed-in browser session to view pages and perform the task the user requested. Information it reads from those pages is handled under the user’s ChatGPT data-control settings.

Before ChatGPT presents a sign-in request, an additional review model examines the request and the intended credential destination for indications of phishing or deception. The user can inspect the website address, preview the sign-in form, and view the live page before proceeding.

Two-factor authentication remains an interactive step for the user. If the site requests a verification or security code, the user supplies it through the secure flow rather than placing it in the conversation. OpenAI explicitly tells users never to paste passwords, security codes, or payment information into chat.

Authentication can persist after the task finishes. The cloud browser maintains its own cookies and signed-in sessions, so a user may not need to authenticate again until the session expires or its browser data is cleared. Users can remove all cloud-browser data or clear it for an individual site from ChatGPT’s settings; clearing a site’s data signs the browser out of that service.

3. This Is a Change From the Cloud Browser’s Launch Limits

At launch, OpenAI’s documentation said the cloud browser could not accept credentials, use autofill or password managers, sign in to websites, or complete payments. It stopped when a task encountered authentication.

The new secure flow specifically removes the sign-in barrier. It does not mean every transaction or website is supported. OpenAI says a site may block automated access, a particular sign-in or transaction step may remain unsupported, or ChatGPT itself may restrict an action. The user may need to take control of the remote browser or finish the last step manually.

Authenticated cloud browsing is also distinct from the browser built into the ChatGPT desktop application. The desktop browser is visible inside the macOS or Windows app and supports its own sign-ins, password management, extensions, downloads, and multiple tabs. The cloud browser instead runs remotely and is intended for delegated Work tasks that can continue in the background.

The remote browser does not inherit the user’s personal browser state. It cannot use existing tabs, history, extensions, saved passwords, cookies, or active sessions from the browser on the user’s device. Each account must therefore be authenticated separately when ChatGPT Work first encounters it.

4. Permissions and Confirmations Still Constrain Actions

Cloud-browser access is available through ChatGPT Work on paid plans in supported regions, excluding Free and Go. OpenAI says availability may vary during the rollout and can depend on workspace permissions. Work itself is rolling out gradually to eligible accounts.

Users can control how the cloud browser approaches websites. The default behavior asks for permission before visiting a new site. Settings also provide an automatic-review option, which pauses when a URL appears unsafe, and an “Always allow” option that OpenAI does not recommend. Individual allow-or-block rules can override the default for specific websites.

Permission to open a site is separate from permission to take a consequential action. ChatGPT is designed to request confirmation before steps that could be difficult to reverse or create a financial, legal, account, or other real-world commitment. OpenAI gives confirming a booking and making a payment as examples.

Users can also ask to take over the cloud browser directly. ChatGPT provides a link that opens the live remote session on a phone or computer, which is useful when the agent encounters an unsupported control or when the user wants to inspect the page personally.

These safeguards reduce credential exposure and accidental action, but OpenAI does not present them as eliminating risk. Its documentation advises users to verify addresses, sign-in previews, screenshots, and confirmation requests, and to stop a task if the browser reaches the wrong website or account.

5. Websites Can Identify and Control ChatGPT Traffic

Support from the destination website remains a practical constraint. Automated-agent detection, bot-management systems, unusual login checks, and unsupported interface elements can prevent a task from completing even when the same site works in a conventional browser.

OpenAI uses Web Bot Auth to sign outgoing cloud-browser requests. The implementation follows the HTTP Message Signatures standard defined by RFC 9421 and includes Signature, Signature-Input, and Signature-Agent headers. The Signature-Agent value identifies ChatGPT, while publicly available keys allow a website or network provider to verify that the request genuinely came from OpenAI’s browser agent.

Major infrastructure providers can use those signatures in their bot controls. OpenAI documents specific recognition paths for Akamai, Cloudflare, HUMAN, and Vercel. Other operators can retrieve OpenAI’s public key, validate the signature headers, and decide whether to permit the traffic.

Authenticated browsing therefore does not give ChatGPT unrestricted access to arbitrary accounts. It gives users a credential-isolated way to authorize a remote browser, while leaving websites able to block the agent and preserving user confirmation for consequential operations.

Frequently Asked Questions

Can ChatGPT see my website password?

OpenAI says usernames and passwords entered through the secure sign-in form go directly to the remote browser. They are not visible to the model and are not stored by ChatGPT.

Does ChatGPT Work use accounts already signed in on my phone or computer?

No. The cloud browser has separate cookies and sessions and does not inherit sign-ins, passwords, history, or tabs from the user’s personal browser.

Will I need to sign in for every task?

Not necessarily. The authenticated cloud-browser session can persist until it expires or the user clears that website’s browser data.

Can ChatGPT complete every booking or transaction after signing in?

No. Website restrictions, unsupported steps, product safety rules, and confirmation requirements may prevent completion or require the user to take over.

Which plans receive authenticated cloud browsing?

OpenAI documents cloud-browser access for ChatGPT Work on paid plans in supported regions, excluding Free and Go. Availability can vary during the rollout and according to workspace settings.

Sources

Share

Share this article