LAUNCH

OpenAI lets Work agents enter your private web apps

Signals Inbox·July 26, 2026·AI Agents

OpenAI now lets ChatGPT Work agents operate inside websites that require a login. You take over the cloud browser once, sign in yourself, and hand control back. The important part is that the login persists, turning private web apps from a hard stop into places where an agent can keep working across sessions.

The Signal, Explained in 3 Minutes

Q1What actually launched?

According to OpenAI’s official announcement, ChatGPT Work agents can now use websites that require an account. When a login appears, you take control of the cloud browser, enter your credentials, and return the task to the agent. The browser keeps that session, so you should not need to sign in again every time.

Q2Why does keeping the login matter?

Because most useful work on the web is private. Email, banking, CRMs, analytics dashboards, supplier portals, admin panels, and company tools all sit behind login screens. An agent that loses access after every task is basically a demo. An agent that remembers the session can return tomorrow, continue the workflow, and handle recurring work without starting from zero.

Q3Wasn’t ChatGPT already able to browse websites?

Yes, but browsing public pages is the easy part. OpenAI launched Operator in January 2025 with a browser that could click, type, and scroll, then folded those abilities into ChatGPT agent. ChatGPT Work launched on July 9, 2026 for longer tasks across apps and files. Just 15 days later, OpenAI added persistent authenticated browsing. That is a fast move from researching the open web to operating inside private accounts.

Q4Does this replace APIs and connectors?

Not completely, but it changes the math. APIs are usually faster and more reliable, while connectors give companies clearer permissions and structured data. But many older or niche tools have weak APIs, expensive integrations, or none at all. A browser agent can use the interface that already exists. That turns almost any web app into something an agent can operate, without waiting for the vendor to build a special integration.

Q5What is the biggest risk?

The agent now has access to more sensitive places. OpenAI warns that a signed-in agent may see emails, files, and account settings, and may perform actions on your behalf. Prompt injection also becomes more serious. A malicious instruction hidden inside a webpage could try to steer the agent toward sharing data, changing settings, or taking an action you never requested.

Q6So why does this signal matter now?

Because the login wall was one of the clearest gaps between an impressive browser demo and a useful workplace agent. Persistent access means ChatGPT Work can now enter the same private tools where people spend their day and return later without repeating the setup. The next test is not whether it can click buttons. It is whether companies trust it with real accounts, recurring jobs, and actions that actually matter.

← Back to the signals