The ChatGPT Work login feature is now rolling out to Plus, Pro and Business subscribers, letting the AI agent sign into websites on your behalf, but a hands-on test reveals it is slower and more awkward than it sounds, and the security picture carries a few wrinkles worth understanding before you hand over your accounts.
The pitch, as OpenAI frames it, is straightforward enough. If it is something you would normally have to open a browser and click through yourself, try asking ChatGPT Work to do it. Setting up utilities, booking a doctor’s appointment, cancelling rescheduled travel, those are the official examples. The feature is available in the web and mobile apps now for eligible account tiers.
How the ChatGPT Work Login Feature Actually Works
Underpinning the whole thing is a real browser built into ChatGPT, one the AI can operate itself. When you switch to agent mode by clicking ‘Work’ at the top of the screen, you can instruct it to log into an account and carry out a task. Websites see it as a sign-in from a new device, and some will let you mark ChatGPT as a trusted operator for future visits.
On credentials: according to the ChatGPT release notes for 25 August 2026, ChatGPT cannot see your username or password, and they are never used in model training or stored by the system. You can either sign in manually when the AI prompts you, or grant it access to a third-party password manager on mobile, which can supply credentials automatically. For the built-in cloud browser, you can manage stored cookies via Settings, which effectively logs the AI out of any site whose cookies you delete.
There is one firm boundary worth noting. According to the OpenAI Help Center, saved cookies do not enable authenticated browsing at launch, and at launch the cloud browser cannot sign into websites or complete payments. That is a meaningful caveat for anyone expecting the feature to run fully autonomously from day one.
Testing It on eBay and Airbnb
In practice, the ChatGPT Work login feature ran into friction almost immediately. On eBay, the process was slow enough that a manual sign-in would have been done several times over before the AI gained access. Verification codes added another layer of confusion: the AI asked for one without making clear where to look for it. Switching to the live browser view inside ChatGPT eventually got things moving, and once in, the AI correctly reported current auction prices, though only after navigating through several wrong pages first.
Airbnb followed a similar pattern. The site was flagged as uncooperative, requiring a manual sign-in through the browser view before the AI could take over. Once it did, it handled dates, locations and price ranges competently enough. Filtering by atmosphere or decor is a different matter; that kind of judgment is harder to delegate in a text prompt.
The broader concern is not whether the AI gets the task done (in testing it did not fail or return inaccurate information once it had access) but whether you want to trust it enough to stop looking yourself. Knowing what an Airbnb actually looks like, or who is bidding on an eBay auction, tends to matter.
The Security Context You Should Factor In
The credential-security question does not sit in isolation. Metomic reports that in 2025, security researchers discovered over 225,000 OpenAI and ChatGPT credentials for sale on dark web markets, harvested by infostealer malware including LummaC2. That is not a flaw in the new login feature specifically, but it is the environment this feature is launching into. Metomic also reported that in February 2025, security researchers at Spin.AI uncovered a coordinated campaign that compromised over 40 popular browser extensions used by 3.7 million professionals, a reminder that the browser layer, however well-intentioned, is a perennial target.
OpenAI states that users stay in control of which websites ChatGPT Work can access and that the AI will always ask for confirmation before consequential actions such as completing a reservation or payment. How it determines what counts as consequential is not explained.
For now, the sign-in flows are too finicky, too slow, and too dependent on manual intervention to genuinely reduce admin. The feature will likely improve. At launch, though, the ChatGPT Work login feature is mostly an interesting preview of where AI agents are heading, not a shortcut that is ready to replace your own clicking just yet.

