Technology

OpenAI's ChatGPT Work Holds Your Authenticated Sessions on Its Servers

ChatGPT Work's cloud browser can now sign into websites and hold those sessions on OpenAI's infrastructure across tasks. The credential is the least of it.

4 min read
A pair of hands rests idle on a wooden desk beside an open laptop, its screen casting a cold blue glow across the room as the cursor blinks autonomously inside a browser window, the
Share

OpenAI says the model never sees your password. The persistent session it holds on its own infrastructure is the actual exposure.

Key takeaways

  • OpenAI updated ChatGPT Work on August 25 to let its cloud browser sign into websites on your behalf, then hold that authenticated session on OpenAI's servers across tasks, including after you leave your device.
  • OpenAI's assurance that the AI model never sees your credentials covers the password only, not the live session token the password unlocks, which sits on OpenAI's infrastructure subject to its policies and legal obligations.
  • The architecture is structurally identical to the custodial exchange model: a centralized intermediary holds persistent access to act on your behalf, and you are trusting a policy promise, not a cryptographic guarantee.

OpenAI updated ChatGPT Work on August 25, 2026, to let its cloud browser sign into websites and maintain those authenticated sessions on OpenAI's servers across tasks, per the official ChatGPT Release Notes. This is a direct reversal: OpenAI's own prior Help Center documentation explicitly stated the cloud browser could not sign into websites or complete payments.

The feature is available on paid plans (Plus, Pro, Business, Enterprise, Edu) and is not available on Free or Go tiers.

What Actually Ships

The mechanics, per OpenAI's cloud browser Help Center page: when the agent hits a login-gated page, OpenAI surfaces a sign-in form, the user enters credentials once, and the authenticated session persists across subsequent tasks on OpenAI's cloud infrastructure. The remote browser runs on OpenAI's machines, not the user's device.

OpenAI puts it plainly:

"You can start a task on web or mobile and let ChatGPT keep working after you leave the conversation or close your computer."

The @OpenAIDevs account framed the user benefit this way:

"Your ChatGPT Work agent can now use websites that require you to sign in... Your login persists across sessions, so you only have to sign in once."

OpenAI says a separate review model checks for phishing indicators before presenting any sign-in form, and that the underlying AI model never sees the username or password. Users can clear session data per-site via Settings. Three permission tiers govern which sites the agent can access: "Always ask" (default), "Auto approve," and "Always allow," which OpenAI's own Help Center labels as not recommended. OpenAI's stated use cases include DMV appointments, passport renewal, utility accounts, and insurance reimbursements.

The Credential Is Not the Point

The "model never sees your password" assurance is technically accurate and almost entirely beside the point. The password is a one-time input. What persists on OpenAI's infrastructure is the authenticated session token, the live credential that grants access to the account. That token can act on financial portals, government sites, email, and healthcare records simultaneously, on servers subject to U.S. law enforcement requests, investor pressure, and OpenAI's internal access controls.

This maps precisely to the custodial exchange argument. An exchange holding your private keys doesn't need to know your seed phrase to act on your bitcoin. OpenAI holding your session token doesn't need your password to act on your accounts. The scope of what it can do with a full browser session cookie is substantially broader and less auditable than a scoped OAuth token, where the user can inspect and revoke specific permissions from the third-party service directly.

A cloud browser session is a full authenticated browser context, not a scoped OAuth token.

OpenAI has already shown it treats the smart speaker category as ambient infrastructure. The cloud browser is the same logic applied to identity and web access: one centralized node accumulates persistent, actionable access to every authenticated service a user touches. As agentic payments become normalized across centralized AI platforms, the political appetite to subpoena that access will grow. Law enforcement doesn't need to break a password when it can compel the company holding the authenticated session.

The falsifiable version of this thesis: if OpenAI published and independently audited a cryptographic proof that session tokens are never accessible to OpenAI employees or government requests, and that the review model cannot log behavior on authenticated sessions, the surveillance risk would be substantially mitigated. A policy promise in a Help Center article is not that proof.

What to Watch

OpenAI will push the use-case surface wider: more government site integrations, more financial account access, more "step away and let the agent finish" workflows. Each expansion increases the value of the session data sitting on OpenAI's servers and, by extension, the attractiveness of that infrastructure to regulators and adversaries. The permission model (three tiers, one of which OpenAI's own Help Center labels inadvisable) will not scale cleanly as agents take on more sensitive tasks. Watch for the first enforcement action or breach that tests OpenAI's policy commitments against a real legal demand.

Sources

Frequently Asked Questions

OpenAI's documentation states the AI model cannot see credentials. It does not address whether OpenAI employees, internal audit systems, or the review model can observe session activity on authenticated accounts. The Help Center is silent on this question, and no independent audit has been published.

OpenAI's release notes and Help Center do not address government or law enforcement access to cloud browser session data. As a U.S.-incorporated company, OpenAI is subject to legal process including subpoenas, National Security Letters, and FISA orders. None of the official documentation specifies what data is retained, for how long, or under what circumstances it would be disclosed.

OAuth grants scoped, revocable token access that the user can audit and revoke directly from the third-party service, with explicit permission boundaries. OpenAI's cloud browser holds a full browser session cookie. The scope of what the agent can do within that session is not bounded by an API permission schema, and the auditability of those actions is not comparable to a standard OAuth grant.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.