Your plan is now a key
OpenAI's developer docs describe Sign in with ChatGPT: "Let users sign in with ChatGPT and use their ChatGPT plan for eligible AI requests in your app." Your subscription stops being something you use and becomes something you lend.
In favour- Real convenience, and scoped: plan usage is "an optional capability" and "does not grant access to their ChatGPT conversations or other account context". Users manage usage in ChatGPT settings.
- It is not a free-for-all. Website sign-in is "currently available to selected commercial partners through a limited trial"; plan usage is documented for open-source and locally hosted apps, with an interest form for the rest.
- The credential lives long. "Access tokens are valid for one hour"; refresh tokens last 30 days and "each successful refresh returns a replacement refresh token with a fresh 30-day lifetime", with "no fixed limit" on successive replacements while each stays valid. In practice that is an open-ended session for whoever holds the file.
- For self-hosted machines the docs say credentials are copied to the VM over a channel such as SSH, and that "host-specific usage attribution and revocation of ChatGPT plan access for transferred sessions are not yet available". A host ID "is not an authentication credential", and for key-derived IDs "OpenAI does not verify possession of the private key".
Our takeTreat a shared plan token like any other long-lived credential: know which machines hold one, keep it out of repositories and images, and assume that today you can turn off the app but not one copy of the session. Convenience arrived before revocation did.
Source: Τεκμηρίωση προγραμματιστών OpenAI, «Sign in with ChatGPT»
← All Focus posts