OpenAI has updated the cloud browser in ChatGPT Work so that tasks can continue on websites that require a sign-in. You enter your credentials yourself through a dedicated form, then hand the rest of the work back to ChatGPT. The username and password never reach the model, and ChatGPT does not store them. That brings accounting software, utility account pages, and similar systems into scope for work that previously stopped at the login screen.
Where the cloud browser actually runs
The cloud browser is a browser dedicated to ChatGPT Work, running on a separate computer in the cloud rather than on your own device. It reads pages, clicks buttons, fills in forms, and works through steps in order. A task keeps running after you close the conversation, and it pauses when it needs input, a sign-in, or a confirmation.
It is available on paid ChatGPT plans, excluding Free and Go. Whether you can use it depends on your region, how far the rollout has reached, and your workspace permissions. You do not select the cloud browser yourself. ChatGPT decides whether to use it based on the request, and it may use a connected app instead when that handles the task directly.
Credentials stay outside the model's view
Sign-in handling is the core of this update. When ChatGPT reaches a login page, it pauses and presents a secure sign-in form. You enter your username and password there, along with a two-factor authentication or security code if the site asks for one.
Credentials entered in that form go straight to the remote browser. The model cannot see them, and ChatGPT does not store them. Before the form appears, a separate review model inspects the request and the destination for signs of phishing or deception. You can also check the website address, preview the sign-in form, and inspect the live site before continuing.
Once you are signed in, the session persists until it expires. The next time a task involves the same site, you can start working without logging in again.
Guardrails on site access and consequential actions
By default, ChatGPT asks for permission before it opens a new site. Settings has a Cloud browser section with three options: always ask, which puts every request in front of you; auto approve, which lets ChatGPT review the URL and pause only when something looks unsafe; and always allow, which permits every site and is not recommended. Per-site allow and block choices override whichever default you pick.
Site access and action approval are separate matters. For steps that are hard to reverse or that create a financial, legal, or account commitment, such as confirming a booking or making a payment, ChatGPT asks for confirmation in chat before proceeding. Allowing a site does not clear its important actions in advance.
If a task gets stuck, ChatGPT will ask you to take over the browser. You can also request a handover yourself, in which case you receive a link that lets you drive the cloud browser directly.
It is walled off from the browser on your device
The cloud browser is entirely separate from the browser installed on your machine. It keeps its own cookies, browser data, and signed-in sessions, and it does not touch your open tabs, browsing history, saved passwords, extensions, or existing logins. Being signed in on your everyday browser does not carry over.
To clear saved data, open Settings, then Cloud browser, then Browser data, where you can wipe everything or handle one site at a time. Clearing a site signs you out of it, so the next task involving that site will ask you to sign in again.
Some sites also restrict access from automated browser agents. A page that opens normally in your own browser may still be blocked here. That decision belongs to the site operator, and OpenAI publishes allowlisting instructions for operators who want to permit access.
The tasks OpenAI has in mind
The examples OpenAI gives include checking restaurant availability, requesting quotes from businesses, finding flights that fit your plans, comparing product availability and local stock, tracking a package using a connected email account and a tracking site, preparing a government office appointment, signing in to a utility account to compare plans, finding and saving apartment listings that meet your criteria, and reconciling invoices and updating records in accounting software.
How much of a task can be completed depends on the site, your level of access, and the steps involved. Some requests are designed to end with a final step you carry out yourself.
The risks have not gone away
OpenAI says it tests for prompt injection, phishing, and unintended actions, while stating plainly that those safeguards do not eliminate every risk. Practical habits matter: never paste passwords, security codes, or payment details into the conversation, always put credentials through the secure sign-in flow, and stop a task immediately if ChatGPT opens the wrong site or starts working from incorrect information.
How you phrase the request matters too. The more specific you are about what should happen, on which site, and how far it should go, the fewer confirmation round trips you get and the less room there is for unintended actions.
Summary
Now that the cloud browser can move past login screens, the range of work you can delegate to ChatGPT Work reaches into the systems companies actually run on. Keeping credentials out of the model, and separating site permission from action approval, are the two mechanisms that make that reach workable. Leaving site access on always ask and starting with errands you can afford to get wrong is the sensible way in.
