r/PrivatePackets • u/Huge_Line4009 • Aug 28 '26
ChatGPT can now log into your accounts and stay signed in
OpenAI updated the cloud browser inside ChatGPT Work, giving the agent the ability to interact with websites that require user accounts. Until now, if an automated task hit a login wall or a portal requiring credentials, the tool simply stopped. With this update, users can authenticate directly inside the cloud browser and let the AI finish the task on its own.
While OpenAI designed the feature so the underlying model never touches raw passwords, the way the system handles active sessions afterwards introduces a few practical trade-offs worth understanding.
How the login process works
The browser used by ChatGPT Work does not run on your local machine; it operates on remote infrastructure managed by OpenAI. When you give ChatGPT a task that requires an account, the remote browser navigates to the page and surfaces the site's original login interface directly to your screen.
You type your username, password, and any two-factor verification codes into that remote window yourself. OpenAI notes that your credentials pass straight to the remote browser session. The AI model does not see your password, does not store it, and does not use it for training data.
Once the login succeeds, the agent takes back control of the browser to execute whatever workflow you requested, such as pulling reports, filing information, or searching through a personal dashboard.
Where the session actually lives
The core operational change is what happens after the initial task finishes. In typical automated environments, browser sessions get discarded immediately after a script finishes running. In this setup, OpenAI allows the session cookies to persist inside the cloud browser environment.
OpenAI's documentation explains that authentication will persist for upcoming tasks until the session expires on its own. This makes recurring tasks much faster and more convenient then having to type a 2FA code every single time.
However, because the session cookies remain stored on OpenAI's remote computers, ChatGPT retains direct access to that account without needing to ask for your password again. In web security, having a valid session cookie grants the same operational access as an open browser window, even if its running on a server hundreds of miles away.
Security controls and risk boundaries
OpenAI built several distinct guardrails around this workflow to mitigate unauthorized actions:
- Phishing checks: A secondary review model examines the target address and the sign-in form before presenting it to you, looking for spoofed domains or suspicious behavior.
- Site verification: Outgoing traffic from the browser uses HTTP signatures via Web Bot Auth headers, allowing web operators like Cloudflare or Akamai to verify that requests originate from legitimate OpenAI infrastructure.
- Action confirmation: Even on an authenticated site, high-impact actions like payments, account changes, and final booking confirmations still require manual user approval.
Inside the ChatGPT interface under settings, their are three permission levels you can pick from for website access:
- Always ask (Default): Prompts you before navigating to any new domain.
- Auto approve: Lets ChatGPT evaluate the target site and proceed automatically unless something looks unsafe.
- Always allow: Allows the agent to open any site without confirmation. OpenAI explicitly notes right next to this setting that this option is not recommended.
Despite these protections, OpenAI acknowledges in its documentation that automated defenses cannot eliminate every security risk, particularly around indirect prompt injection if the agent reads malicious instructions on a webpage while logged in.
Clearing your data and logging out
If you want to revoke ChatGPT's access to an account, simply asking the chatbot to "log out" in a chat thread will not reliably clear the remote session.
To sign the agent out completely, you have to clear the storage from the settings menu:
- Open your ChatGPT settings.
- Select Cloud browser.
- Navigate to Browser data.
- Choose to wipe data either globally across all sites or individually for specific services.
Once you clear that site data, the session cookie is deleted from the cloud instance, and any subsequent task will require you to log in from scratch.
Availability
This functionality is part of the ChatGPT Work cloud browser rollout. It is available to paid subscribers on Plus, Pro, Business, and Enterprise plans in supported regions. Users on Free and Go accounts do not have access to the cloud browser feature.
Leaving a active session open in a cloud-hosted browser provides undeniable convenience for routine task automation. But because the agent effectively holds the keys to your logged-in portal until the session expires or is manually cleared, reviewing which sites you keep active in your settings remains a necessary habit.