ChatGPT Work now auto-signs into websites using stored cookies
OpenAI's ChatGPT Work feature can automatically log into user accounts by saving login credentials as cookies in its built-in browser. This enables the AI to perform tasks without repeated authentication, but raises privacy concerns. Users are advised to be selective about which sites they allow ChatGPT to access.
The new capability is exclusive to ChatGPT Pro and Plus subscribers, functioning through the agentic ChatGPT Work system. During initial use, users manually enter credentials for a site, and the system stores them as cookies within its built-in cloud browser. Subsequent requests bypass the login prompt entirely, allowing the AI to access accounts independently. The feature is designed for practical tasks like scheduling appointments, comparing utility plans, or reviewing medical costs through insurance portals.
Testing revealed inconsistent performance. The Windows desktop application successfully auto-authenticated into Amazon and eBay accounts after initial logins, but the ChatGPT website version encountered blocks from Amazon's security systems. Repeated access attempts also triggered rejections, suggesting sites may flag the AI's automated activity. Users can manage stored credentials through Settings, under Cloud Browser, where saved cookies can be reviewed and deleted individually or in bulk.
This feature could significantly shift how users interact with AI agents, reducing friction for routine online tasks but introducing new privacy considerations. Individuals who grant ChatGPT access to sensitive accounts—banking, healthcare, or workplace systems—may face heightened risk if credentials are compromised or if the AI misuses stored data. Employers and organizations could also be affected, as employees using ChatGPT Work might inadvertently expose corporate account information. Users may need to weigh convenience against control, carefully selecting which sites to authorize and regularly auditing stored cookies.