
OpenAI's ChatGPT Work agent just got a meaningful unlock: it can now operate on websites that require you to be signed in. The catch -- and this is important -- is that the agent doesn't log in for you. You do it yourself, and then hand the wheel back.
The handoff model
Here's how it works in practice. When the agent hits a page that requires authentication, it pauses and prompts you to take over the virtual browser. You log in manually through that browser window. ChatGPT agent pauses and prompts you to take control via "... → Take over browser", and while you're in control, screenshots are not captured -- protecting passwords and other sensitive data you enter.
After you complete the required step and return control, the agent attempts to continue from the prior workflow state; in some cases it may need to re-establish the run or prompt you again if takeover or resume cannot be completed. Think of it as a human-in-the-loop authentication checkpoint, not a fully autonomous login flow.
The session persistence is the real quality-of-life win here. Cookies persist across sessions for convenience, just like a regular browser. To clear saved logins or cookies, you sign out of sites and remove cookies in your ChatGPT data control settings. So you authenticate once, and subsequent agent runs on that same site can pick up where they left off.
Don't miss what's next in AI
Join 300,000+ engineers and researchers who get the signal, not the noise.
- Full access to in-depth AI research breakdowns
- Be the first to know what's trending before it hits mainstream
- Daily curated papers, repos, and industry moves
