← All posts / Tools

ChatGPT Work Learns to Log In: Cloud Browser Sign-In, Webhook Tasks, and the Agentic Web's New Front Door

OpenAI's August 25 update lets ChatGPT Work agents complete sign-in flows on websites, trigger scheduled tasks from Gmail, Slack, and GitHub events, and brings task automation to free users — with guardrails attached.

ChatGPT Work Learns to Log In: Cloud Browser Sign-In, Webhook Tasks, and the Agentic Web's New Front Door

For most of the agent era, one trivially human action has been the hard wall between AI assistants and real work: the login form. An agent could read a page, summarize it, even fill in a form — but the moment a website asked “who are you?”, the human had to take the wheel. On August 25, 2026, OpenAI quietly removed that wall for ChatGPT Work, and in the same release notes rebuilt its scheduled tasks system around event triggers. Together, the two changes turn ChatGPT from a chatbot that occasionally browses into a persistent operator of the authenticated web.

Website sign-in through the cloud browser

The headline feature is cloud browser sign-in. On eligible plans, ChatGPT Work on the web, iOS, and Android can now detect that a task requires a website account and prompt the user to complete a sign-in flow. The critical design decision: credentials are entered in the dedicated sign-in flow, never in the chat itself, and the model never sees what you type.

That separation matters. In OpenAI’s official documentation, the flow is explicit — follow the sign-in request, enter details in the sign-in window, and the authenticated session lives in a cloud browser that stays separate from your local browser profile. Connecting your local profile is not part of the deal. According to Neowin’s report, OpenAI states that credentials are not exposed to the model, not used for training, and not stored by ChatGPT; users can lean on existing password managers to fill in authentication details, and can wipe browser data per-site or wholesale from ChatGPT settings at any time.

Once authenticated, the agent continues browsing and completes the task inside the signed-in session — which persists for future tasks. OpenAI’s own scenario list sketches the ambition: setting up utilities for a new apartment, booking DMV, passport, or vet appointments, checking medical costs through an insurance portal, finding an in-network doctor, preparing vehicle registration paperwork, matching apartment listings, scheduling package pickups, submitting reimbursement paperwork, sourcing job candidates, and pushing invoices from email into accounting software. These are exactly the chores that eat evenings — unglamorous, multi-step, and gated behind passwords.

Guardrails remain. Confirmation is still required before consequential actions such as completing a reservation or making a payment, and OpenAI notes that website-access and action-confirmation requirements still apply. Enterprise and Edu workspaces are excluded from website sign-in entirely — a telling signal about where OpenAI sees the compliance risk.

The rest of the agentic browser stack

The sign-in feature didn’t arrive alone. The same August 25 changelog entry, titled “Browser extensions, site tools, and cloud sign-in,” extends the ChatGPT browser extension beyond Chrome to Microsoft Edge, Brave, Opera, and Vivaldi, configured through Settings > Computer Use in the ChatGPT desktop app. All five support tab mentions and browser control; Opera alone lacks side chat.

More technically interesting is Site tools, which OpenAI calls WebMCP. In the desktop app’s built-in browser, ChatGPT Work and Codex can now invoke actions a website itself offers — a document editor exposing “find a section” or “add a comment” as callable tools, for instance. Rather than an agent scraping pixels and simulating clicks, the website declares its capabilities and the agent calls them directly. That is the Model Context Protocol’s original promise — standardized tool interfaces — now applied to ordinary websites. It requires GPT-5.6 Sol or GPT-5.6 Terra, excludes GPT-5.6 Luna, and like sign-in is unavailable in Enterprise and Edu workspaces.

Scheduled tasks grow a nervous system

The second half of the update transforms scheduled tasks from cron jobs into event-driven agents. Tasks can now trigger when supported events occur in Gmail, Slack, or GitHub — filter Gmail by sender or subject, watch selected Slack channels, or react to pull request reviews, comments, commit updates, and merges. OpenAI’s documentation suggests the pattern: “When one of my pull requests receives new review feedback, summarize the feedback and prepare a revision plan.”

The plumbing here is webhooks. TechTimes notes the new attack-route concerns this introduces — an inbox that can trigger automation is also an inbox that can be aimed — though the mitigations are structural: the ChatGPT Slack app must be a member of each watched channel, the connected GitHub app must have access to each watched repository, apps must be connected and their access approved first, and in managed workspaces administrators can control availability. An event-triggered task can’t also run on a time schedule, near-simultaneous events may be merged into one run, and a Scheduled view lets users review pending events or force a run.

OpenAI also made tasks shareable — publish a task so colleagues can customize it and connect their own accounts — and expanded scheduled tasks to ChatGPT Free users, capped at three active tasks, no webhook triggers, and recurring tasks limited to once per day.

Why this is bigger than a feature drop

Step back and the shape of the platform is visible. ChatGPT now has: a browser that spans five desktop browsers plus a cloud browser; authentication that survives across sessions; websites that can expose native tools to the agent; and a trigger system that reacts to the three places work actually happens — email, chat, and code. Each piece shipped separately would be incremental. Together they form the minimum viable stack of an agentic operating layer: identity, action, perception, and eventing.

The strategic read is equally clear. Anthropic’s Claude platform moved computer use, browser tool, Skills, and Files APIs to general availability the week before; Google is pushing Gemini deeper into Workspace with Ask Gemini in Chat. OpenAI’s answer is to make its consumer-and-SMB-facing product, ChatGPT Work, capable of operating the logged-in web end-to-end. The exclusion of Enterprise and Edu from the riskier features suggests a deliberate go-to-market sequence: prove the safety model on smaller workspaces first, harden the audit story, then unlock the largest contracts.

There are honest caveats. A persistent authenticated session is a honeypot if account compromise ever crosses the threshold — prompt injection through a watched Slack channel or a crafted email now has a bigger blast radius, which is precisely why admins can lock triggers down. And the promise that credentials never touch the model is a design claim users must currently take on trust, even if the architecture — a separate sign-in flow outside the chat context — is the right one.

For now, the agentic web has its front door, and it opens with a password the AI never sees.