ChatGPT signs in to your accounts now and stays signed in

OpenAI extended the cloud browser in ChatGPT Work on 25 August with something it explicitly could not do before. The browser, which runs on a remote machine and works through tasks for you, can now handle sites that require a login. Shortly before, OpenAI's own documentation said the opposite. The cloud browser would not accept credentials, would not use password managers and would not sign in anywhere.
Here is how it works. When the agent hits a login page, it stops and shows a form. You type the username and password yourself, plus a two-factor code if the site asks for one. Before that form appears, OpenAI says a separate review model checks where your data is going and whether the page looks like phishing. You can inspect the address and a preview of the form first. Password managers are supported.
The password is not the problem
On credentials OpenAI is clear. "Credentials entered through the secure form go directly to the remote browser", the help page says. The model does not see the username or password, they are not stored, and they are not used for training. What that same training toggle fails to cover is a separate story.
What stays behind is the session. "The authentication will persist for future tasks until it expires, so you do not need to sign in each time", OpenAI writes. A few paragraphs down the wording softens to "may remain active". Either way, the cookie that carries your login now sits in the cloud browser. And a cookie like that is enough to walk into an account without the password and without the second factor.
The machine keeps running after yours is off
The cloud browser is not a window on your device. It runs on its own computer in the cloud and keeps working "including after you close your computer or turn off your phone". It has its own cookies, its own browser data, its own logins. It does not touch your open tabs, your history, your saved passwords or your existing sessions. That is the good news. The other half is that your session now sits somewhere you cannot see, while your laptop is shut in a bag.
The setting OpenAI warns you about itself
Under Settings, Cloud browser you decide which sites the agent may open. There are three levels. "Always ask" is the default and prompts for every new site. "Auto approve" lets ChatGPT check the address and only stop when something looks unsafe. The third is "Always allow", which permits everything. OpenAI's own note next to it reads: "This is not recommended." An approved site is still not an approved action. Bookings and payments are confirmed one by one.
How to sign the agent back out
You cannot do it from the website. Go to Settings, Cloud browser, Browser data and clear the data either for every site or for one specific site. Clearing a site's data signs you out there, and the next task will ask you to sign in again.
Who gets it
That depends on the plan. The cloud browser ships in ChatGPT Work on the paid plans except Free and Go. For the sign-in feature inside it OpenAI names Plus and Pro. The rollout is staggered and OpenAI publishes no country list, only "supported regions", so whether it already works in a given country cannot be read from that. With other features the company spells out an EU exclusion plainly, as it did with Computer History.
OpenAI concedes the residual risk itself. It tests for prompt injection, phishing and unintended actions, the documentation says, and "those safeguards do not eliminate every risk". How real that class of risk is was demonstrated in August on several AI browsers. The cloud browser was not among them. The ingredient that makes those attacks dangerous, it now has as well. A session that stays signed in.





