Agentic ChatGPT Work browser sign-in persistence was added by OpenAI in its August 25 release notes, introducing an agentic browser capability in ChatGPT Work. The feature allows ChatGPT Work to authenticate on login-gated sites by surfacing the login screen for credentials or a security code and then continue working while the user steps away, with the session potentially remaining signed in for future tasks after authentication. OpenAI listed the capability as live in ChatGPT Work’s browser on both web and mobile in the same August 25 notes.
ChatGPT Work’s agentic browser can operate on login-gated websites by presenting the site’s login screen for credential entry or a security code. OpenAI states the browser supports password managers for that step, and the model cannot see usernames or passwords; those credentials are not stored or used for training. After authentication, the agent can continue executing tasks on the site without requiring repeated immediate input.
Following successful authentication, the session may remain signed in for subsequent tasks, which gives the agent persistent access to the account that would otherwise require the user to open it interactively. OpenAI notes that safeguards focus on protecting the password itself but do not extend to the authenticated session the password unlocks. Sessions can be cleared individually per site from Settings > Cloud browser, and the feature is available in ChatGPT Work’s browser on both web and mobile.
The preceding section summarizes the agentic sign-in mechanism and session persistence without additional commentary or analysis.
ChatGPT Work’s agentic browser presents a site’s login screen to collect credentials or a security code and supports the use of password managers for that input. OpenAI says the model cannot see usernames or passwords, and those credentials are not stored or used for training. Sessions opened by the agent can be cleared individually per site from Settings > Cloud browser. The feature is available in ChatGPT Work’s browser on both web and mobile.
After a user authenticates, the agent can continue executing tasks using the authenticated session without repeated interactive sign-ins. Authenticating once hands the agent a persistent foothold on an account that would normally require the user to open it interactively. OpenAI notes that safeguards focus on protecting the password itself but do not extend to the authenticated session the password unlocks. The design assumes the user is not actively watching and OpenAI frames the tradeoff as security over convenience. OpenAI also identifies an upside in that users do not need to re-enter passwords for an assistant to file a form or retrieve a statement.
OpenAI presented these controls and tradeoffs in its August 25 release notes. The release notes state that session-level safeguards beyond password protection are not provided.
Agentic ChatGPT Work browser sign-in persistence is present in ChatGPT Work and functions to authenticate on login-gated sites and maintain signed-in sessions for subsequent tasks. Users can clear sessions individually per site from Settings > Cloud browser, and the browser supports password managers while the model cannot see or store usernames or passwords. OpenAI notes that safeguards protect passwords but not the authenticated sessions and frames the design tradeoff as prioritizing convenience and persistent access over additional session-level security.


