explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsdictionaryagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

On this page

  • TL;DR — what changed and what did not
  • How ChatGPT Work's secure website sign-in works
  • What can you ask it to do on a signed-in site?
  • Cloud browser vs desktop browser vs your Chrome session
  • What people are asking about ChatGPT cloud browser sign-in
  • The security boundary is better, not complete
  • What this changes for ChatGPT Work
  • Related on explainx.ai
← Back to blog

explainx / blog

ChatGPT Work Cloud Browser Can Now Sign In to Websites

ChatGPT Work can now use signed-in websites from a remote cloud browser. Here is what OpenAI protects, what persists, and when to avoid it.

Aug 27, 2026·8 min read·Yash Thakker
ChatGPT WorkOpenAIBrowser AgentsAI SecurityComputer Use
go deep
ChatGPT Work Cloud Browser Can Now Sign In to Websites

On August 26, 2026, OpenAI updated ChatGPT Work's cloud browser to handle the step that blocks most useful web automation: signing in to websites. The agent can now pause, hand you a secure credential form, and continue on the authenticated site after you complete login and two-factor authentication.

The headline needs one important correction. OpenAI says the model cannot see or store credentials entered through the secure form, but the remote browser does retain cookies and signed-in sessions until they expire or you clear them. That is what makes repeat tasks useful — and what makes session management the part users need to understand.

This is an incremental but practical extension of ChatGPT Work, not a new model. It turns Work from a public-web research agent into a browser agent that can reconcile invoices, check utility plans, track account-bound information, and prepare bookings on supported sites.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

TL;DR — what changed and what did not

table · 2 cols
QuestionDirect answer
Can it use signed-in sites?Yes, on supported sites through ChatGPT Work's remote cloud browser
Who enters the password?You, in a secure sign-in form; never in the chat
Can the model see the password?OpenAI says no
Does OpenAI store the credential?OpenAI says it does not store the username or password entered there
Does the login persist?Yes, potentially — cookies and the authenticated session can remain for later tasks
Can it make a payment without asking?It is designed to request confirmation before consequential financial, legal, or account actions
Will every site work?No — sites can block automated agents, and some steps remain unsupported
Who gets it?Paid ChatGPT plans in supported regions, excluding Free and Go; rollout and admin policy can vary

How ChatGPT Work's secure website sign-in works

OpenAI's cloud browser guide describes a delegated browser running on a separate remote computer. You start a task from ChatGPT Work on web or mobile; ChatGPT decides whether to use a connected app, a plugin, the cloud browser, or a combination.

When the browser reaches a supported login page, the sequence is:

  1. ChatGPT pauses the task and asks you to sign in.
  2. An additional review model checks the request and destination for signs of phishing or deception.
  3. You inspect the website address, sign-in preview, and live page.
  4. You enter credentials and any two-factor code in the secure form.
  5. Those values go directly to the remote browser rather than through the model conversation.
  6. ChatGPT resumes the task using the resulting authenticated session.

That boundary matters. It is closer to taking over a remote browser at the login screen than giving an LLM a password in its prompt.

Credentials and sessions are different secrets

OpenAI's wording is precise: the username and password entered in the secure form are not visible to the model and are not stored as credentials. After authentication, however, the cloud browser keeps its own cookies and signed-in state.

table · 2 cols
SecretWhat OpenAI says happens
Username and password entered in secure formSent directly to the remote browser; hidden from the model; not stored as credentials
Two-factor codeEntered during the secure flow, not pasted into chat
Session cookie after successful loginKept in the cloud browser and may work on later tasks
Cookies from your personal browserNot imported
Existing tabs, history, passwords, and extensionsNot shared with cloud browser

This distinction is the central takeaway: password isolation reduces credential exposure; it does not make an authenticated browser session disposable.

You can revoke that retained access from Settings → Cloud browser → Browser data. OpenAI lets you clear one site's data or all cloud-browser data. Clearing a site's data signs the remote browser out of that account.

What can you ask it to do on a signed-in site?

OpenAI lists account-bound examples including comparing utility plans, tracking a package using connected email plus a carrier site, reconciling invoices in accounting software, and preparing a DMV booking for approval.

The strongest tasks share three properties: they are multi-step, browser-shaped, and still have a clear review point.

Try prompts like these:

text
Sign in to my utility account when prompted. Compare my current plan with every
fixed-price option available to this account. Build a table of monthly fee,
unit rate, contract term, and cancellation fee. Do not change the plan.
text
Use the invoices in my connected email and the signed-in accounting site to
reconcile August payments. Flag mismatches and duplicates. Do not edit, submit,
or delete any record until I approve the proposed changes.
text
Find the earliest DMV appointment within 30 km on a weekday morning. Prepare
the booking, show me the location and cancellation policy, and stop before the
final confirmation.

The explicit stopping rule is not ceremonial. It gives the agent a smaller action budget and makes the intended confirmation boundary unambiguous.

Cloud browser vs desktop browser vs your Chrome session

OpenAI now documents three distinct browsing contexts. Treating them as interchangeable is how users accidentally grant more access than a task needs.

table · 4 cols
Browser surfaceWhere it runsSession sourceBest fit
ChatGPT Work cloud browserRemote OpenAI computerSeparate cloud-browser cookiesBackground tasks that can continue after you leave
ChatGPT desktop built-in browserInside the macOS or Windows appIts own app browser stateVisible, attended browsing with tabs, downloads, and annotations
Codex Chrome extensionYour normal Chrome profileExisting tabs, cookies, sign-ins, and extensionsTasks that genuinely require your current Chrome session

The desktop built-in browser guide says the local surface can be opened from Work or Codex with Command+Shift+B on macOS or Ctrl+Shift+B on Windows. Unlike cloud browser, it is designed for you to follow and annotate the page as the agent works.

This mirrors the choice Anthropic now exposes between its Cowork built-in browser and Claude in Chrome: use an isolated browser when separation is valuable; use your real profile only when existing authenticated state is necessary.

What people are asking about ChatGPT cloud browser sign-in

Is this the same as “Sign in with ChatGPT”?

No. Sign in with ChatGPT is an identity-provider flow: a partner site uses your ChatGPT identity to create or access an account, similar to “Continue with Google.” Cloud-browser sign-in is the opposite direction: you authenticate the remote browser to an existing third-party website so ChatGPT can complete a task there.

Can ChatGPT keep working after I close my laptop?

Yes. OpenAI says the cloud browser can continue on its remote computer after you close the browser, computer, or phone. It pauses when it needs information, a login, or confirmation. That background execution is the main difference from attended computer use inside Codex.

What stops it from visiting a phishing site?

OpenAI says an additional review model checks sign-in requests and destinations for phishing or deception, and the interface shows the address and a preview before you enter credentials. Users can also choose Always ask, Auto approve, or Always allow for website access, plus per-site rules.

Keep the default conservative. OpenAI itself labels Always allow as not recommended. Site permission also does not remove confirmation for consequential actions.

What if the website blocks ChatGPT?

The task may fail even when the same page works in your regular browser. Sites can restrict automated agents, login flows can be unsupported, and some transactions still require takeover or manual completion.

For website operators, OpenAI's allowlisting documentation says cloud-browser requests use Web Bot Auth and HTTP Message Signatures under RFC 9421. Signed requests let supported edge providers distinguish ChatGPT's agent traffic from an anonymous bot, but the site still decides whether to admit it.

The security boundary is better, not complete

Secure credential entry solves one narrow problem: the model does not need the password as text. It does not solve the broader browser-agent problem.

Once authenticated, the agent can read account data and interact with whatever the session exposes. A malicious page can still attempt indirect prompt injection, and a mistaken instruction can still target the wrong account, record, or transaction. OpenAI says its safeguards test for prompt injection, phishing, and unintended actions but do not eliminate every risk.

Use the cloud browser with these defaults:

  • Keep website access on Always ask for sensitive workflows.
  • Check the hostname and sign-in preview before typing anything.
  • Enter secrets only through the secure form, never in the conversation.
  • Give the agent read-only goals before edit or submit goals.
  • Require a stop before payments, bookings, messages, deletions, or policy changes.
  • Clear a site's browser data when repeat access is no longer useful.
  • Prefer a purpose-specific connected app or plugin when it exposes narrower permissions.

The AgentForger incident is a useful reminder that agent authorization is a system property, not a single safe input box. Credential isolation, site permissions, constrained tools, and human confirmation have to work together.

What this changes for ChatGPT Work

ChatGPT Work already had the ability to research, coordinate longer tasks, and create finished materials. Signed-in cloud browsing closes the gap between “find public information” and “finish a workflow inside my account.”

That is a meaningful product step, but not blanket permission to hand every SaaS session to an agent. Start with low-consequence accounts, keep site approval explicit, and build repeatable workflows around reviewed proposals, not autonomous commitments. The useful mental model is a remote junior operator with a temporary browser session — capable of doing the clicks, but still requiring a clear scope and a human at the irreversible step.

Related on explainx.ai

  • ChatGPT Work vs Codex: what actually changes
  • OpenAI Codex computer use on Windows and mobile
  • Claude Cowork's built-in browser
  • Claude in Chrome browser extension and safety guide
  • What is indirect prompt injection?
  • ChatGPT AgentForger workspace-agent security incident
  • ChatGPT Work thread orchestration
  • Login with ChatGPT and Codex OAuth explained

Official references: Using cloud browser in ChatGPT · Using the built-in desktop browser · Cloud browser allowlisting

Details are accurate as of August 27, 2026. Cloud-browser availability, supported sites, plan access, and confirmation behavior can change during rollout; check OpenAI's current help documentation before using it for sensitive workflows.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

Related posts

Aug 21, 2026

Codex Usage Limits and sub2api: What Tibo Said About Fraud vs OAuth

Tibo Sottiaux investigated reports that Codex usage limits felt different across accounts. Many affected users were routing through sub2api — converting a personal ChatGPT subscription into shared API traffic. That pattern is not supported and gets flagged by fraud-prevention systems. explainx.ai maps sub2api vs legitimate Sign in With ChatGPT, what Sol-era drain complaints mean, and what developers should do instead.

Aug 27, 2026

Claude Cowork Built-In Browser: Side-Panel Web Agent (Aug 2026)

Anthropic shipped a native browser inside Claude Cowork on August 27, 2026 — no extension, no shared cookies, rolling out over the next week on desktop paid plans. Claude in Chrome is generally available on paid plans too. explainx.ai maps when to use each and what changed from July's Claude Code browser.

Aug 25, 2026

Codex Plus Gets the 5-Hour Limit Back — Pro Plans Stay Uncapped (For Now)

OpenAI Codex lead Tibo Sottiaux posted August 25 that the rolling 5-hour usage window comes back tomorrow for Plus accounts on ChatGPT Work and Codex — a policy he had teased, then postponed. Pro $100 and Pro $200 subscriptions keep the 5-hour gate disabled for the upcoming months. explainx.ai maps the bait-and-switch reactions, the compute argument, and what it means if you picked Codex over Claude because the cap was gone.