Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
- ChatGPT can sign in to your website accounts without your input.
- The built-in browser uses cookies to store your login credentials.
- Use caution with the sites you allow ChatGPT to access.
AI agents can complete a variety of requests without your intervention. One task that does typically need your input is logging in to a password-protected website. But a new option available with ChatGPT can automatically sign you in to one of your online accounts, at least under certain conditions.
Also: How to use ChatGPT Work - and my top 10 tips for getting started with agentic AI
Launched on Tuesday, the new skill is accessible through the agentic ChatGPT Work, which carries out assignments on its own based on your requests. Available only for ChatGPT Pro and Plus accounts, this new option uses ChatGPT's built-in browser to keep your session signed in for future tasks. How? By storing your login information in cookies, just like any other browser.
How this works
The first time ChatGPT needs to access one of your website accounts, you'll be prompted to enter your username and password or your passcode. You can manually type them or autofill them from a third-party password manager. The AI will then sign in to your account as expected. The next time ChatGPT needs to log in to that same site, you won't be prompted. Instead, the AI will use the cookies generated from the previous session to sign you in without your input.
Also: You can use 70+ Adobe tools without leaving ChatGPT now - here's how
OpenAI suggests that you can ask ChatGPT Work to do any of the following:
- Figure out utilities for a new apartment and sign up for the right plan.
- Book a DMV appointment or fill out your passport renewal forms.
- Check X-ray and bloodwork costs through your insurance portal.
- Find profiles of people who fit your job description and are open to work.
To put this to the test, I fired up the ChatGPT Windows app, which uses its own built-in cloud browser. I asked ChatGPT Work to log in to my Amazon website account and list all the items and prices on my public wish list. The first time I did this, the AI naturally prompted me to sign in with my Amazon credentials.
But upon subsequent attempts, ChatGPT automatically signed in to my Amazon account without my input.
Hiccups
I did bump into a couple of hiccups.
First, trying this on the ChatGPT website resulted in an error in which Amazon blocked the attempt from the ChatGPT cloud browser. In my testing, only the ChatGPT Windows app worked.
Second, the first two times I tried this with the Windows app, the requests were successful. But when I attempted it a couple more times, access to Amazon was blocked. When I asked ChatGPT about this issue, the AI suggested that Amazon may be rejecting access because of recent or repeated activity.
Also: I let ChatGPT Work and Claude Cowork loose on my files - only one made me nervous
What do you do if you no longer want your credentials stored this way? Just as you can delete a cookie from any other browser, you can also delete the ones stored in the ChatGPT browser. To do this, go to Settings and select Cloud Browser. Under Browser data, click the setting for Cookies. You can then review the saved cookies for logged-in sites and delete any or all of them.
I tried this by telling ChatGPT Work to sign in to my eBay account and list the items on my watchlist. With the eBay cookies stored in the cloud browser, I didn't need to enter my credentials on subsequent attempts. After I deleted the cookies and tried again, I had to enter my username and password.
Is it a privacy risk?
This type of skill sounds convenient. But here's the big question: Is it a privacy risk?
OpenAI says that ChatGPT can't see your username or password and that your credentials are never viewed by the AI model or used in model training. You control which websites ChatGPT Work is able to access. The AI will also always ask for confirmation before consequential actions, such as completing a reservation or payment.
But that brings us back to the same question: Is this a privacy risk?
"This sounds like a privacy risk, but I would characterize it more accurately as an identity, security, and authorization risk," said Morey Haber, chief security advisor at identity security provider BeyondTrust.
"OpenAI states that ChatGPT is not exposed to the username or password (credentials)," Haber noted.
Also: I loved ChatGPT Desktop until OpenAI gutted it to make room for Codex and Work
"However, protecting credentials does not necessarily protect an identity from harm or hijacking. Once authentication succeeds, the AI agent is operating inside an authenticated session with whatever privileges and entitlements the user possesses. At that point, a threat actor may not need the password since attacking the session itself becomes the actual prize," Haber said.
To highlight the risk, Haber pointed to AI attack vectors like prompt injection. Here, an attacker can hijack an AI session to capture data or perform unwanted actions. Cybercriminals have already proven that they can steal session cookies and tokens. Put all these elements together, and your login details could be at risk, just like cookies from other browsers.
"Using the same credentials repeatedly for these connections, regardless of how they are stored, is a common problem that privileged access management and non-human secrets management have attempted to address for decades," Haber added.
"So, is it a privacy risk," he asked? "Potentially, but the larger concern is delegated identity security risk. The password is merely the key to authentication. Once the door opens, cybersecurity needs to control what the AI agent is allowed to do inside especially if best practices are ignored."
Should you not use this option?
Not necessarily. But you should exercise caution over which sites you let ChatGPT access.
"Users trying this feature should start with lower-stakes sites where the task is routine, and hold off on anything tied to sensitive information, such as finances or healthcare, until OpenAI provides more detail about how persistent access is protected and how to review or revoke it," said Shane Barney, chief information security officer at cybersecurity software provider Keeper Security.
Also: I tested ChatGPT vs. Claude to see which is better - and if it's worth switching
"It's important to check your account settings regularly for any sessions or connected access you no longer recognize, and do not assume access ends automatically just because the task does," Barney said.









English (US) ·