OpenAI has updated the proxy browsing capability of ChatGPT Work. After a user completes authentication on a website that requires login, the system can continue to handle tasks on their behalf, and the relevant login status may be retained for subsequent operations. This feature is now available on both web and mobile platforms.
Tasks can be continued after a single login.
According to the update notice released on August 25th by OpenAI, when users assign tasks to ChatGPT Work, if the target website requires login, the system will first display a login page. Users will then need to enter their account information, password, or security verification code. Once authentication is completed, the proxy can continue to perform operations on the website without the user having to remain on that page the entire time.
OpenAI indicates that this process supports password managers. The company states that the model itself cannot see usernames and passwords; these details are not stored and are not used for training purposes either.
The session may be retained for subsequent tasks.
The convenience of this feature is that users do not have to re-enter their passwords repeatedly, allowing the assistant to continue submitting forms, retrieving bills, or completing other operations within the site. However, at the same time, the logged-in state may be retained, enabling continued access to the same account after proxying.
- Supported platforms: web and mobile ChatGPT Work browsers
- Login method: Users manually enter credentials or verification codes.
- Clearing method: You can delete sessions by site in the settings at Cloud browser.
The dispute focuses on the duration of permissions.
The article mentions that this means the system obtains not just a one-time login permission, but a session entry that can be used continuously. Compared to the password itself, what is more noteworthy is the account access capabilities corresponding to the session after logging in.
OpenAI emphasizes in the description that users can leave after assigning tasks to agents, allowing the system to continue processing them. However, this also raises a more direct issue: even when the user is not present, the agent can still continue to operate within the logged-in account.
The original text argues that existing protective measures mainly cover the password input phase and do not truly eliminate the risk of privileges associated with the persistence of logged-in sessions. In other words, although the system cannot see the password, as long as the session remains valid, it still has nearly the same level of access to the user's account as the user themselves.
Currently, users can manually clear their browsing history and sessions on each site, but this control method still relies on post-event management rather than gradual authorization based on individual operations.










