ChatGPT Work Adds Cloud Browser Sign-Ins

OpenAI added signed-in website support to the ChatGPT Work cloud browser on August 25, allowing users to complete supported web tasks from an isolated remote browser. According to OpenAI's help documentation, the browser pauses for users to enter credentials and complete two-factor authentication, while tasks can continue after the user leaves the conversation. The feature is available on paid ChatGPT plans in supported regions, subject to workspace controls.
OpenAI added support for signed-in websites to the cloud browser in ChatGPT Work on August 25. According to OpenAI's help documentation, the feature lets ChatGPT operate a browser running on a separate cloud computer, including reading pages, clicking controls, entering form data, and carrying out steps on supported public and authenticated websites.
The feature is available in ChatGPT Work for paid plans in supported regions, excluding Free and Go plans, OpenAI's documentation states. Availability can also depend on workspace permissions and the staged rollout.
How authenticated tasks work
When a cloud-browser task reaches a supported login page, ChatGPT pauses and asks the user to sign in through a secure form. Users complete their own username, password, and any required two-factor authentication steps, according to OpenAI's help article. The system can also pause for user input or confirmation during a task.
OpenAI documents examples including checking utility-account plans, tracking packages, reconciling invoices in accounting software, locating DMV appointments, and finding apartment listings. It also notes that task completion depends on the target website, the user's access, and the steps involved; some workflows require user review or a final action by the user.
ChatGPT chooses whether to use a connected app, plugin, cloud browser, or a combination of those tools, rather than requiring users to manually select the browser. Users can begin a task from web or mobile, and the task can continue after they close the conversation or their computer.
Isolation and session handling
OpenAI's cloud-security documentation describes Work cloud tasks as running on OpenAI-managed infrastructure rather than on the user's device. It states that a cloud task does not inherit the device's local files, desktop applications, existing browser sessions, or private-network access. The documentation also identifies VM-backed sandboxes as the current supported execution path and says Work Cloud uses the Codex task-execution harness.
Notebookcheck reports that credentials entered through the secure form go directly to the remote browser, are not shown to the model, and are not stored or used for model training. The same report notes that authentication may persist for later tasks until it expires, meaning an authenticated browser session remains in the cloud environment after the password entry itself is complete.
MacStories reports that OpenAI uses an additional review model to examine sign-in requests and credential destinations for phishing or deceptive behavior before presenting the sign-in form. That safeguard is distinct from the user's responsibility to inspect the destination and approve the requested task.
Operational implications
For enterprise deployments, the distinction between credentials and authenticated sessions is important. Browser automation systems commonly reduce password exposure by isolating credential entry, but session cookies and other authentication artifacts still require controls over retention, access scope, expiration, and auditability.
OpenAI's security guide states that connected apps operate with the permissions of the authorized account, which may be an individual, shared, or agent-owned account. It also states that workspace and feature-specific controls govern Work access, cloud browsing, connected apps, and networking. For Business, Enterprise, and Edu workspaces, OpenAI documents encryption in transit and at rest, and states that workspace data is not used to train its models by default.
Teams evaluating authenticated agent workflows can use these boundaries to assess whether a task should run through a narrowly scoped account, require a confirmation step, or remain outside automated browsing altogether. OpenAI advises users to check task results and sources before relying on them.
Key Points
- 1ChatGPT Work can now complete supported signed-in website tasks from an isolated cloud browser after users enter credentials and MFA.
- 2OpenAI documentation separates credential entry from model visibility, while authenticated sessions may persist in cloud execution environments for later tasks.
- 3Agentic browser deployments generally shift security review toward session lifecycle, approval gates, audit logs, and least-privilege account configuration.
Scoring Rationale
Authenticated browser automation expands the set of business workflows ChatGPT Work can handle beyond public-web research. The isolated execution model, session persistence, and workspace controls are directly relevant to teams assessing agent security and enterprise deployment boundaries.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems