The Cookie That Follows You Out of ChatGPT: OpenAI's __obi Ad Pixel Explained
An independent researcher reverse-engineered OpenAI's ad measurement pixel, finding a SameSite=None cookie that quietly links what you do on ordinary shopping sites to your ChatGPT account.
On September 20, 2026, an independent security researcher published a detailed reverse-engineering write-up of OpenAI’s advertising infrastructure that quickly rose to 321 points and 161 comments on Hacker News. The finding at its core is simple to state and uncomfortable to sit with: OpenAI operates an ad-measurement system that can connect your browsing on ordinary websites — retailers, course platforms, ticketing services — to your ChatGPT account, through a cookie most users have never heard of.
The cookie is called __obi. It is set by a collector at bzr.openai.com — “bzr” standing for “bazaar,” OpenAI’s internal name for its ads platform — and it is scoped to the entire .openai.com domain with a one-year lifetime. What makes it unusual is its configuration: SameSite=None, meaning it is deliberately built to be transmitted on cross-site requests. The researcher, who verified the mechanism on their own phone with two independent capture methods and months of observed traffic covering 936 distinct advertiser pixels across 1,029 hostnames, found it is the only OpenAI cookie configured this way. Every other OpenAI identifier was blocked by the browser on those same cross-site requests.
How the mechanism works
The chain begins inside ChatGPT itself. On chatgpt.com, the client generates 16 random bytes and calls a backend endpoint that returns a cryptographically signed RS256 JWT. The token binds your account subject (sub), a 22-character obi identifier, an expiry of 60 seconds, and — notably — a consent_decision field reading analytics_allowed. The client then posts this token cross-site to bzr.openai.com/v1/obi/sync, and the response sets the __obi cookie: Domain=.openai.com; HttpOnly; Max-Age=31536000; SameSite=None; Secure. The cookie value and the JWT’s obi value are identical. From that moment, the identifier rides along with you.
The receiving end lives on advertiser websites. Any company buying ads on ChatGPT can install a small piece of OpenAI code — the oaiq.min.js SDK served from bzrcdn.openai.com — exactly the way retailers have long installed Meta and Google tracking tags. And here the researcher documented a subtle point that defeats a plausible defense: the SDK itself has a code path that omits credentials on its requests, but it doesn’t matter. The browser attaches cookies to the <script src> request that loads the SDK before any of OpenAI’s code runs. Loading the tag is the disclosure. On the researcher’s device, a single __obi value was transmitted to OpenAI from twelve commercial websites under thirteen distinct pixel IDs — including Chewy, Wayfair, ThriftBooks, Eventbrite, HelloFresh, Coursera, and SeatGeek. Every request was accepted with a 202.
What travels with it
The SDK does not merely phone home with an identifier. It harvests identity material from the advertiser’s page, sorting it into four sources that OpenAI’s own payload labels: in for values the advertiser deliberately passes, and fm, ht, and js for values the SDK scrapes from form fields, rendered page text, and the tag-manager bus. In observed traffic, scraped identity outnumbered advertiser-supplied identity 685 events to 255.
The tag-manager bus turned out to be the largest source of email addresses. The SDK replaces window.dataLayer.push with its own function, reads adobeDataLayer, and even locates renamed Google Tag Manager layers by parsing the l= parameter off the gtm.js script tag. Current versions extract email and phone from it; version 0.1.31 also collected names and geography until the scope was narrowed on August 27. Emails, phone numbers, and names are SHA-256 hashed before transmission — but country, region, city, and postal code are sent in the clear. Postal code was the single most-harvested form field: 100 events across 28 sites.
URLs are reduced to origin plus path before sending, and none of 23,929 observed URLs carried a query string. But paths survive, and the paths that reached the collector included a medical condition, a debt-solutions funnel, and a litigation intake form. Automatic matching — controlled from OpenAI’s Ads Manager — was enabled for 638 of 881 pixels with a known setting, including every credit and lending advertiser observed. OpenAI’s denylist does exclude passwords, one-time codes, card numbers, Social Security numbers, dates of birth, medical history, diagnoses, and court fields.
The consent question at the center
This is where the story moves from technical curiosity to governance problem. OpenAI’s cookie policy lists __obi under “Analytics cookies,” one year, and it is the only entry in that section. The policy describes analytics cookies as helping OpenAI understand how its services perform. Meanwhile, OpenAI runs analytics and marketing as two separate consent choices (oai_consent_analytics versus oai_consent_marketing), and every sync token the researcher decoded carried consent_decision: analytics_allowed. In other words: a user who allows analytics and refuses marketing still gets a cross-site identifier that feeds the ads platform.
The researcher sent the mechanism and two pointed questions to OpenAI’s press and privacy addresses on September 14 — why __obi is classified as an analytics cookie, and whether analytics-consenting, marketing-refusing users still receive it. OpenAI Support acknowledged the inquiry, said the observations would be shared internally for review, and did not answer either question.
There are real limits worth stating plainly. The mechanism was observed on Chrome for Android. Safari’s Intelligent Tracking Prevention blocks all third-party cookies, and every iOS browser runs on WebKit, so the mechanism does not operate on iOS at all. Roughly one ChatGPT session in five produced a sync token. And the final join — OpenAI resolving the cookie to your account server-side — follows from the design but was not directly observed. The server did accept every event with the cookie attached.
Why this matters beyond adtech
None of the building blocks here are new. Meta built the structural equivalent years ago: a logged-in account, third-party cookies on pixel fires, off-site conversions resolved to a profile. As the researcher put it, the mechanism is standard adtech. What has no precedent is running it on an AI chat product. People tell these products things they would never post on a social network — symptoms, legal worries, financial stress — and these products increasingly act on their behalf. Advertisers installing the pixel cannot see any of this; __obi lives on a domain their scripts cannot read, and they have no way to know their visitors are being resolved to a ChatGPT identity.
As ChatGPT’s advertising business scales, the __obi episode crystallizes the question that will define AI-platform privacy for years: when your conversational assistant and your ad network belong to the same company, what exactly did you consent to — and who gets to check?