Why Your ChatGPT Agent Now Only Needs Your Password Once | Edition 284
Edition 284 — ChatGPT Work agents can now log into sites for you — and remember it, so you never repeat that step again.
For as long as agentic AI tools have existed, there's been one wall they couldn't get past: the login screen. An agent could read a public page or draft inside an open document, but the moment a task needed your loyalty account, your work dashboard, or any site that simply wanted a password, it stalled and handed the job back to you. OpenAI just said that wall is down for ChatGPT Work agents — and the real fix isn't only that a human can log in on the agent's behalf. It's that the login sticks.
How the handoff actually works
When a running task hits a site that needs a login, the agent pauses and hands you control of the same cloud browser it's been driving. While you're in control, ChatGPT stops capturing screenshots of that window — specifically so a password or one-time code you type is never recorded or seen by the model, per OpenAI's own documentation. Once you finish signing in and hand control back, the agent picks the task back up exactly where it left off.
One limit worth flagging: some sites can still block automated browsers outright, and any second factor you're sent — a text code, an authenticator app — still needs to be entered by you, live, during the takeover, the same as the password itself.
The actual news is what didn't used to persist
Takeover-mode logins already existed before this announcement — that part isn't new. What's new is the piece that used to reset every session: the login itself. Cookies now stick around across sessions the way they would in an ordinary browser, so a site you signed into on Monday is still signed in on Friday, whatever task the agent is running by then. You can still sign out and clear cookies yourself from ChatGPT's data controls whenever you want a clean slate.
Why the word "persists" is the whole story
Before this, handing an agent a recurring job on a site you sign into meant either logging back in every session or not delegating that kind of task at all — the login was a per-task interruption, not a one-time setup. Now it's infrastructure you build once. That's what opens the door to genuinely new categories of delegated work: checking a loyalty balance, actually completing a booking on a site that requires an account, or pulling a report out of an internal tool sitting behind your company's login — none of it requiring you to sit there re-authenticating on every single run.
Where it ships
ChatGPT Work — the agent product this lives in, powered by OpenAI's new GPT-5.6 model family — launched July 9 and is rolling out to Pro, Enterprise, and Edu plans first, with Plus and Business close behind.
| Before | After | |
|---|---|---|
| Site needs a login | Agent stops and hands the task back to you | Agent pauses once, you log in, it continues |
| Next time on that site | You log in again from scratch | Login and cookies persist — no repeat step |
| Password exposure | Screenshots paused during takeover | Unchanged — still true, just more useful now |
| What becomes possible | Public, no-login pages only | Loyalty accounts, bookings, internal tools behind auth |
What this means for you
Set the login up once, deliberately. The next recurring task you're weighing whether to hand to a work agent, check whether it lives behind a sign-in you dread repeating — that's now the strongest case for delegating it, not a blocker.
The security model didn't change, only the payoff did. Your credentials were already protected during takeover; persistence just means you stop paying that setup cost every single session.
Office agents already cut real research work from two days to minutes in Edition 277. Persistent login is what lets that same agent keep working on the parts of your job that live behind a password.