OpenAI has added authentication support to the ChatGPT Work cloud browser. The change allows the AI agent to access password-protected websites and handle tasks that previously required users to guide it through each login page.
When ChatGPT Work reaches a sign-in screen, it pauses and displays a secure form. Users enter their username, password, and any required two-factor authentication code themselves.
OpenAI says those credentials go directly to the remote browser. The model does not see them, store them, or use them for training.
How ChatGPT Work Website Login Works
The new login flow is designed to keep the user in control of account access. ChatGPT Work does not enter credentials on its own. Instead, it waits for the user to complete the authentication step before continuing with the requested task.
Password managers work with the feature. OpenAI also uses a separate review model to check whether a destination page appears to be a phishing site before showing the login form.
After the user signs in, the browser session can remain active for later tasks until it expires. That means users may not need to log in again every time they ask ChatGPT Work to use the same website.
Session Controls and Sign-Out Options
Users can remove stored browser data through Settings. This can be done for an individual website or across all sites, allowing users to sign out and clear active sessions when needed.
The session runs in a cloud browser on a remote machine. It can continue operating even after the user’s own device is turned off.
Tasks ChatGPT Work Can Complete After Login
Authentication opens up a wider range of tasks across websites that require an account. OpenAI highlighted several examples of what users can ask ChatGPT Work to do after they sign in:
- Book DMV appointments
- Book medical appointments
- Check insurance costs
- Submit reimbursement paperwork
- Find job candidates
- Manage invoices across platforms
The agent can work within an authenticated session, but it still needs direct approval before taking consequential actions. For example, ChatGPT Work asks for explicit user confirmation before finalizing a reservation or making a payment.
That distinction matters. Login access allows the agent to move through websites and prepare actions, while confirmation remains required for actions with meaningful consequences.
ChatGPT Work Login Availability
The website login feature is available to ChatGPT Plus, Pro, and Business subscribers on web and mobile.
The feature brings authenticated browsing to users who need help handling account-based workflows, while retaining login, sign-out, and approval steps within the process.
Security Considerations for Authenticated Cloud Browsing
OpenAI acknowledges that authenticated cloud browsing carries residual risk. The browser session is held on a remote machine, and a session cookie can provide access to an account without requiring the password or a second authentication factor again.
OpenAI says it tests for prompt injection and unintended actions. Still, the company states that its safeguards do not remove every risk.
The phishing review step, credential handling approach, and confirmation requirement for consequential actions are part of the controls described for the feature. But an active session remains an important consideration because it can continue after a user’s device is off.
Scheduled Tasks Also Gain Event-Based Triggers
Alongside the ChatGPT Work login update, OpenAI announced changes to Scheduled Tasks.
Scheduled Tasks can now respond to events rather than only running at pre-set times. Supported events include:
- New Gmail messages
- New Slack messages
- GitHub pull request activity
Scheduled Tasks is also expanding to free-tier users. Free users can have up to three active tasks. Webhook triggers are not included for the free tier, and tasks can run no more than once per day.

