On six launch partners, what name, email, and profile picture actually reveal, and why becoming a login provider is a bigger ambition than building a better chatbot
OpenAI became an identity provider last week. The footnote is worth reading.
Anti-AI
00
Skeptic
02
Neutral
00
Pro (practical)
00
Pro (hyped)
01
← Anti-AI · Pro-AI →
If you've signed up for anything online in the last five years, you've seen the row of buttons. "Continue with Google." "Sign in with Apple." Maybe Microsoft. You click one, get sent to a familiar page, click approve, you're in — no new password, no email confirmation loop. That row just got a new addition.
OpenAI launched "Sign in with ChatGPT" on August 2, as a live beta. Six launch partners: Airtable, GitLab, HubSpot, Notion, Supabase, and Vercel. The flow is exactly what you'd expect — click the button on a supported app, authenticate with your ChatGPT account, approve what gets shared. The partner app receives three things: your name, your email address, and your profile picture.
That's it. Except that's not quite all that happens.
What's actually going on
Here's the object lesson. When you sign in to Notion with your Google account, Google learns that you use Notion. That sounds trivial — it isn't. Over time, Google builds a picture of which apps you use, which devices you sign in from, how often, and from where. This is called the login graph, and it's one of the reasons Google's identity business is valuable. Not just because it's convenient, but because it adds context to everything else Google already knows about you.
"Sign in with ChatGPT" creates the same structure. OpenAI now learns which apps you connect to via your ChatGPT login. A Notion user who signs in with ChatGPT is a different kind of person than a GitLab user who does the same. ChatGPT already knows your conversations. Now it knows your software footprint.
That combination — what you've asked an AI, and which apps you use — is meaningful data. Not necessarily misused, but meaningful.
| Provider | What they already had | What they gain when you use their login |
|---|---|---|
| Email, search history, Drive, Maps location | Which third-party apps and services you use | |
| Apple | Apple ID, device usage, App Store purchases | Which apps you connect — with a throwaway email option |
| Microsoft | Microsoft account, Office files, LinkedIn (many users) | Which apps you sign in to |
| ChatGPT (new) | Your conversations with an AI assistant | Your software footprint — which apps you link |
The footnote I mentioned
Before deciding how much to trust OpenAI with your login, there's one thing worth knowing. A class action filed May 13, 2026 alleges that OpenAI embedded Facebook Pixel and Google Analytics tracking code inside ChatGPT, silently transmitting user account identifiers and email addresses to Meta and Google without adequate disclosure. OpenAI has not publicly responded to the allegations. The case has not been adjudicated.
I'm not saying this makes "Sign in with ChatGPT" unsafe. I'm saying: if your assumption going in is "OpenAI is careful and private with my data," the full picture is more complicated than that. This launched eight weeks after that case was filed.
Source spread
- RuntimeWire — OpenAI rolls out Sign in with ChatGPT as an identity layer for apps [builder] — confirms the August 2 launch, six named partners, data shared, and competitive positioning vs Google/Apple/Microsoft login
- JustThink AI — ChatGPT as Your Universal App Login? [skeptic] — analysis of what OpenAI gains from the login graph; more critical framing than the announcement
- TechTimes — Sign in with ChatGPT: What OpenAI Retains [skeptic] — the class action context, what partner apps don't receive, and what OpenAI's auth logs do see
What's real / What deserves a side-eye
What's real:
- This is genuinely convenient. If you already have a ChatGPT account, you don't need a new password or a new email verification on any of the six launch platforms. That's a real quality-of-life improvement.
- The underlying technology — OAuth 2.0 and OIDC (a standard for verifying identity, the same one Google and Apple use) — is well-understood and auditable. OpenAI didn't invent a new pipe; they plugged into an existing standard.
- Enterprise administrators get real controls: disable Sign in with ChatGPT across the whole organization, or restrict it to an approved list of apps. That's a useful governance lever for anyone managing a workplace deployment.
What deserves a side-eye:
- "Your login activity" is contextual data even when the token itself is minimal. OpenAI knowing you log in to Airtable, HubSpot, and Vercel tells them you're probably running a startup or product team. That's useful signal to have about a user, and it's accurate to name it.
- The pending class action about tracking pixels changes the trust calculation slightly. Not conclusively — the case hasn't been decided — but "we didn't tell you we were sharing your data with Meta and Google" and "trust us with your login" are harder to reconcile.
- Six partners is a small beta. The full list of places you can actually use this is short right now. The interesting question is how fast it expands, and whether the next wave of partners includes anything involving sensitive personal or financial data.
What to do about it
- Check if you already use any of the six launch partners. Airtable, GitLab, HubSpot, Notion, Supabase, Vercel. If you use any of these, you may already see the "Sign in with ChatGPT" button as an option when creating or connecting accounts.
- For low-stakes apps, the convenience is real. If you're setting up a Supabase account for a side project, using ChatGPT login is probably fine. The data stakes are low and the saved password hassle is real.
- Hold off on sensitive work accounts. Linking your ChatGPT identity to apps that handle sensitive client data, medical records, or financial information is a different calculation. The class action context matters there.
- If you manage a workplace ChatGPT deployment, configure the admin controls. Enterprise admins can disable Sign in with ChatGPT org-wide or restrict it to approved apps. Worth setting before employees start connecting company accounts without coordination.
- Follow the expansion. The six-partner launch list is small. The risk profile changes as more apps — especially ones outside developer tools — start offering this option. Revisit this decision when the list grows.
Further reading
- RuntimeWire — OpenAI rolls out Sign in with ChatGPT as an identity layer for apps — launch confirmation and partner list
- JustThink AI — ChatGPT as Your Universal App Login? — analysis of what the login layer means for OpenAI's platform ambitions
- TechTimes — Sign in with ChatGPT: What OpenAI Retains — the class action context and what OpenAI's auth logs see that partner apps don't receive
- OpenAI Help — Sign in with ChatGPT — the official documentation on what's shared and how Enterprise controls work
Liked this? Get the weekly digest.
Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.
Your take
How'd I do on this one?
What did I miss?
Tell Samwise (and Sam).
Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.