ChatGPT Work Cloud Browser: Secure Website Sign-In and Business Use Cases
A practical guide to using ChatGPT Work across signed-in websites on web and mobile without exposing passwords to the model, including business use cases, approvals, security controls and limitations.

ChatGPT Work can now sign in to websites on web and mobile
Watch the original post and video on X
ChatGPT Work can use its own cloud browser to open websites, read pages, click, type and complete multi-step tasks. When a site requires authentication, Work pauses for the user to enter credentials and two-factor codes through a secure sign-in flow. Those credentials go directly to the browser and are not visible to the model. The session can remain signed in for future work, while website permissions and confirmation before consequential actions remain under user control.
- The cloud browser runs separately from the browser on your phone or computer and keeps its own cookies, history and sessions.
- Enter credentials and 2FA through the secure sign-in form or direct takeover—never in chat.
- ChatGPT asks before accessing new websites and before consequential actions such as submitting information, booking or paying.
- A task can start on web or mobile and continue in the cloud after the user's computer is closed.
- Availability depends on plan, workspace, region and rollout; some sites and CAPTCHAs block automated browsers.
- Business workflows should separate Read, Draft, Prepare and Execute, with an explicit human approver for each risk level.
What is the ChatGPT Work cloud browser?
The cloud browser runs on ChatGPT Work's cloud computer, not inside the browser on the user's phone or laptop. It can open pages, read content, click, type and continue a multi-step workflow across a website.
Users can start the task in ChatGPT Work on web or mobile and follow progress in the conversation. Because the browser runs in the cloud, the task can continue after the user's computer is closed.
Work may choose a browser, a plugin or both. A structured integration is often more reliable and auditable, while the browser extends coverage to websites that do not expose a suitable connector or API.
How secure sign-in keeps credentials away from the model
Official OpenAI documentation says usernames and passwords entered through the secure form are not visible to the model, are not stored by ChatGPT as credentials and are not used for model training. Do not paste passwords into the chat; that bypasses the protected flow.
- ChatGPT navigates to the website and pauses at sign-in.
- The user inspects the domain and sign-in preview.
- The user enters credentials and 2FA through the secure form or takes over the page where offered.
- Credentials go directly to the browser and are not exposed to the model.
- After authentication, ChatGPT continues inside the signed-in session.
- The user can clear browser data to sign out of one or all sites.
Start a task from web or mobile
- Open ChatGPT on web or mobile and start a task in Work.
- State the outcome, website, data scope and actions that require approval.
- Approve website access after verifying the domain.
- Sign in yourself when the login screen appears, including 2FA where required.
- Follow progress and answer decision questions in the conversation.
- Review the summary, evidence and proposed actions before consequential changes.
Business and personal use cases from the announcement
The common pattern is a task that spans pages and steps while the user retains decision rights. Success is not click volume; it is a correct, reviewable outcome with human approval at the right boundary.
- Government and utilities — arrange service, appointments and renewal paperwork.
- Healthcare — find an in-network doctor, book around availability and prepare reimbursement paperwork.
- Housing — save matching listings and compare insurance coverage with a landlord issue.
- Commerce and returns — restock from a photo, schedule pickup and monitor new drops.
- Travel and pets — cancel rescheduled tickets or book a vet appointment.
- Recruiting — find candidates with specified experience and draft outreach.
- Finance operations — move invoices from email into accounting software.
- Property and vendor operations — draft inquiry responses and prepare portal action items.
- Small business — prepare permit applications and analyze the latest ad campaign.
Marketing, ads and sales workflows
Ad decisions need the full funnel, not a single dashboard screenshot. Connect clicks to landing conversion, qualified lead, sale and revenue, then define who must approve budget changes, pauses and publishing.
- Open ad dashboards and collect spend, CPM, CTR, CPA and ROAS for a defined period.
- Test the landing page, form and conversion path as a user would experience them.
- Inventory live creative and group it by hook, format and offer.
- Prepare a campaign review with Scale, Hold, Refresh and Investigate recommendations.
- Research prospects and draft outreach while stopping before send.
- Update lead status or notes only with scoped permission and approval.
Design human approval in four levels
OpenAI says Work asks for confirmation before consequential actions such as submitting information for a booking or completing a payment. Organizations should add their own approval requirements for customer data, external messages, spending and destructive changes.
- Read — inspect, compare and summarize without changing data.
- Draft — fill forms or compose messages without submission.
- Prepare — present the final action, cost, recipient and expected impact.
- Execute — submit, book, pay, cancel or update only after confirmation.
Website permissions, browser data and session cleanup
Cloud browser settings let users review website access individually, use relevance-based approval or allow selected sites. OpenAI's documentation does not recommend the least restrictive always-allow setting.
The cloud browser maintains separate cookies, browsing data and signed-in sessions. It does not automatically use personal open tabs, history, saved passwords or extensions. Clear its browser data when an account is no longer needed, a team member changes roles or a sensitive project ends.
- Use Always ask for new or high-risk sites.
- Allow only domains required for the workflow.
- Review active signed-in sessions periodically.
- Clear data after offboarding, access changes or suspicious activity.
- Never place passwords, API keys or recovery codes in prompts or files.
Limitations to test before production
Test the target account and website before promising the workflow. A demo that has not passed authentication, CAPTCHA, permissions, mobile, errors and recovery is not a production system.
- Some websites block automated browsers or use CAPTCHAs the agent cannot complete.
- Unsupported authentication methods may require the user to complete the step manually.
- Availability depends on plan, region, workspace settings and rollout.
- Current documentation says web/mobile website sign-in is available on Plus and Pro, not Enterprise or Edu.
- Page content can contain prompt injection and must be treated as untrusted context.
- Browser interaction is more fragile than an API when a site's layout or flow changes.
Connect cloud-browser work to an AI ads and conversion system
The browser can inspect ad platforms and landing pages, but decisions still require trustworthy measurement. OG Solution's AI Ads & Conversion System connects pixels, server-side events, CRM feedback and dashboards so AI sees the journey from impression to qualified lead and revenue.
The agent can then analyze changes, prepare an action plan and stage updates while a human approves budget, publishing or data submission.
Discuss an AI ads and conversion systemTurn a browser task into repeatable AI automation
A browser is useful for sites without APIs and steps that require visual context. Recurring work still needs explicit triggers, schedules, inputs, stop conditions, logs, retries and approvals. Prefer a plugin or API for structured steps where one exists.
OG Solution designs controlled workflows across cloud browsers, Google Workspace, CRM, LINE, plugins and schedules, with audit trails and human approval instead of fragile macros that fail whenever a page changes.
Explore AI automation servicesProduction checklist
- Name the outcome, website, account and data the agent may read.
- Define Read, Draft, Prepare and Execute permissions and approvers.
- Use least-privileged accounts instead of administrator access.
- Never send passwords, API keys or recovery codes in chat.
- Verify the domain and sign-in preview.
- Capture evidence such as URLs, timestamps, screenshots or confirmation numbers.
- Test errors, CAPTCHA, session timeout and human takeover.
- Measure accuracy, time saved, failure rate and remediation work.
Frequently asked questions
Can ChatGPT Work sign in to websites?
Yes, where website sign-in is available for the account and rollout. Work pauses for the user to authenticate and then continues in the signed-in cloud-browser session.
Can ChatGPT see my username or password?
Credentials entered through the secure sign-in form go directly to the browser and are not visible to the model. OpenAI says ChatGPT does not store those credentials or use them for model training. Never paste passwords into chat.
Can a task continue after I close my computer?
Yes. Work on web or mobile uses a browser in the cloud, so a supported task can continue while you monitor or respond through the conversation.
Can ChatGPT book or pay without asking?
Work requests confirmation before consequential actions such as submitting booking information or completing a payment. Review the recipient, cost, details and impact before approval.
Does the cloud browser use passwords saved in my Chrome profile?
No. It has a separate profile, cookies, history and sessions and does not automatically use your personal open tabs, extensions or saved passwords.
Does it work on every website?
No. Some sites block automation, require unsupported sign-in or present CAPTCHAs. Availability also depends on the plan, region, workspace and rollout.
Is website sign-in available for Enterprise or Edu?
Current OpenAI documentation says web/mobile website sign-in is available for Plus and Pro and is not available for Enterprise or Edu. Verify the latest documentation before rollout.
How is browser automation different from a plugin or API?
Browser automation interacts with the visual interface and covers sites without integrations, but is more fragile. Plugins and APIs exchange structured data and are usually better for stable, repeatable workflows.
Sources
- [1] Browser — Let ChatGPT research and interact with websites — OpenAI · ChatGPT Learn · accessed 2026-09-27
- [2] ChatGPT Work website sign-in announcement — ChatGPT on X · accessed 2026-09-27