OpenAI · ChatGPT Work

Cloud browser — authenticated web action execution

ChatGPT Work can use an OpenAI-hosted cloud browser to navigate and interact with external websites, including separately authenticated website sessions. It can perform multi-step web tasks and execute consequential external actions such as submitting information to make a booking or completing a payment, subject to applicable website-access controls, authentication, user takeover and runtime confirmation controls. Not every website is supported, and the capability does not confer unrestricted transaction authority.

Recorded characteristics

Function
A ChatGPT Work task can operate an OpenAI-hosted browser, interact with website interfaces and authenticated sessions, and perform multi-step external web actions. For defined consequential actions, OpenAI documents runtime confirmation/user-control mechanisms. OpenAI describes the cloud browser as "a hosted tool a Work task can use to interact with websites"; ChatGPT decides when to use it based on the request, and tasks can continue after the user leaves the conversation. Execution environment: the browser runs in OpenAI-managed infrastructure, separate from the user's local browser environment; this capability does not control the user's local computer. Boundary: this record covers managed remote browser execution only. Web search, Deep Research, connected-app and MCP actions (recorded separately under ChatGPT Workspace Agents → App and MCP server actions), the ChatGPT desktop app's local built-in browser, developer API computer use, and scheduling/event triggering are excluded. OpenAI states that "the cloud browser, web search, connected apps, and code or shell networking are separate capabilities."
Data access
Website content accessed through an enabled cloud browser, subject to applicable access controls, and information supplied to the task. The hosted browser does not inherit the user's local browser profile, open tabs, existing sign-ins, saved passwords, password manager or browsing history. Where supported, users sign in to websites separately through a hosted sign-in flow; OpenAI states credentials entered through the secure sign-in form are not seen by the model, are not stored by ChatGPT and are not used in model training. Authenticated sessions can remain active for future tasks until browser data is cleared (Settings > Cloud browser > Browser data), which signs the user out. Supported website interactions can include public forms and can combine information from an authorized app with a website task.
Actions
Can take actions
External actions
Yes
Human confirmation
Conditional
Permission basis
User permissions
Administrative control
Enterprise administrators must enable both Work access and cloud browser access (Admin Console > Permissions & roles > Workspace capabilities > Cloud computer capabilities); these capabilities can be configured independently of Work Cloud access, and browser access is reviewed separately from code/shell network access. "Use password manager" is a separate workspace permission covering the local in-app browser and cloud browser. Users manage website permissions in Settings > Cloud browser: Always ask, Auto approve (automated relevancy/risk checks) and Always allow (OpenAI does not recommend it). These govern website access only; OpenAI states neither grants new app permissions nor approves every action on a website. The connected-app confirmation settings (Always ask, Any changes, Important actions, Never ask) govern connected apps and are not recorded as Cloud browser controls. Desktop browser site rules do not become cloud-browser restrictions. Users can clear hosted browser data.
Default state
Conditional
Availability
Available in ChatGPT Work on paid ChatGPT plans other than Free and Go; OpenAI states cloud browsing is available in all regions on those plans. Availability can depend on plan, workspace settings and rollout, and the browser may not appear immediately during rollout. Enterprise admins must enable cloud browsing. Website sign-in is not available in every workspace or rollout.
Licensing
Included with eligible paid ChatGPT plans (not Free or Go); no separate charge is documented in the reviewed sources.
External model or provider
OpenAI (OpenAI-hosted browser and models).
Limitations and uncertainty
Human confirmation recorded as conditional (confirmation requirements vary by action). OpenAI documents runtime confirmation for consequential actions, but its current documentation uses differing formulations of the strength and universality of that guarantee: the Browser page says ChatGPT Work "will always ask for confirmation before consequential actions, such as submitting your information to book an appointment or completing a payment"; another passage on the same page says it "is trained to ask for confirmation before consequential actions, such as completing a booking or payment"; the ChatGPT Work cloud security page says "consequential actions can still require separate confirmation". These are not collapsed into a universal technical guarantee. Not every browser interaction requires confirmation. User control: when sign-in is required the task pauses; the user signs in via the secure form or directly in the cloud browser and selects "I'm done" to return control; if ChatGPT is blocked, the user can take over its computer. Permission basis recorded as user_permissions: actions on signed-in sites run through the website session the invoking user personally authenticates in their own cloud browser, held in that user's Cloud browser settings for their future tasks; public-site actions use no account authority. Not established: whether a persisted session could be exercised in any shared, agent-owned or non-interactive context; how OpenAI's infrastructure operation interacts with target-side attribution. The Browser monitor page also describes the ChatGPT desktop app's local built-in browser; desktop-specific statements (sensitive-action wording on submitting information, changing permissions or deleting data; browser_use_full_cdp_access; local browser authority) are not used as evidence here. The Help Center article "Using cloud browser in ChatGPT" returns only a bot-check page to automated retrieval and is not used as evidence or a monitor. Not publicly established: full browser implementation details; complete browser-action audit trail (OpenAI warns not to assume every browser interaction appears in compliance exports); exactly-once execution, retry semantics, duplicate-side-effect prevention and rollback after partial external change; universal target-side attribution; universal website compatibility (some sites block automated browsers or require CAPTCHA); universal MFA or authentication support; universal transaction or payment authority; maximum browser actions or task duration; native cloud-browser scheduling or event triggers.

Evidence