Tech X Telco

ChatGPT security history: check an unfamiliar sign-in

OpenAI has added a record of recent sign-ins and security changes. Learn where to find it, how to read an unfamiliar event and what to do next.

Michel Elijah ·

Editorial illustration of a laptop account-security screen with a recent sign-in list and a phone, without showing real account details.

If a sign-in alert catches you off guard, the hardest part is often deciding whether it was you on a different device or someone else using your account. ChatGPT now gives you a place to check recent account-security events before you start guessing.

What you need to know

On the web, OpenAI says to open ChatGPT Settings, choose Security and login, then Security history. The new view can show sign-ins, sign-outs and changes to your password, multi-factor authentication, passkeys or other security settings. It records past events. Use Active sessions separately to inspect or end current sign-ins.

Find the event before you react

Security history was announced on 25 September 2026. Start in the account you actually use—personal and work accounts can have different activity. Look at the event type, time, device and location together. OpenAI cautions that some device or location details can be approximate or unavailable. A city you do not recognise is a reason to investigate, not by itself proof that somebody broke in.

Think back to actions that may have generated the entry: a new browser, a replacement phone, a passkey you added, or a deliberate sign-out. If the timing and device still do not make sense, save the event details you can see before changing settings. That record may help support you later. Do not share screenshots containing email addresses, device details or recovery information publicly.

History and sessions answer different questions

The two views are useful together, but they are not interchangeable.

  • Security history

    What recent sign-ins, sign-outs or security-setting changes were recorded? It can include activity that is no longer active.

  • Active sessions

    Which first-party OpenAI browser or app sessions are currently known, and which can you sign out? It does not show recently signed-out sessions.

Check whether the session is still active

OpenAI places Active sessions in ChatGPT’s security settings. It can show the device or browser, an approximate location, the sign-in time and whether a row is your current session, where those details are available. Review the list for a device or app you cannot account for. A session you have already signed out of should not be expected to remain there.

Active sessions does not manage a third-party app you connected, a “Sign in with ChatGPT” session used only for another service, or Codex CLI sessions. OpenAI also says the view is unavailable for accounts linked to an organisation’s SSO sign-in. Those limits matter if a list looks shorter than you expected.

What if you did not make the change?

Treat an unexplained password change, new passkey or MFA change more seriously than a vague location mismatch. If you use a password and suspect it was exposed or reused, change it from the official site. OpenAI then advises logging out of all sessions and contacting support about activity you did not authorise. If you use the API, its guidance also calls for deleting exposed keys and checking usage.

OpenAI says logging out of all devices may take up to 30 minutes to reach other ChatGPT sessions. Turning on MFA adds protection to future sign-ins, but does not cancel existing logins. That is why OpenAI’s guidance puts password and session action ahead of relying on MFA alone after a suspected compromise.

  • Type the official ChatGPT address yourself rather than following a link in a surprising email.

  • Record the unfamiliar event’s time and device details without posting them publicly.

  • If you use a password and think it is exposed, change it; then sign out of all sessions.

  • Review passkeys and MFA methods, and contact OpenAI Support about changes you did not authorise.

  • If you use the API, inspect usage and revoke any key that may have been exposed.

Read next: set up a passkey without losing your way back in

A useful habit even when nothing looks wrong

You do not need to turn every unfamiliar-looking entry into an emergency. A quick check after setting up a new device helps you learn how your own activity appears. Keep a unique password if you use one, review your sign-in methods, and make sure your account recovery options still work before removing an old device.

Security history gives you another piece of evidence. It cannot replace your judgement about whether an action was yours, and it should not be mistaken for a complete audit of every connected service. If something is unexplained, use the account controls and OpenAI’s support route rather than trying to diagnose a breach from one approximate location label.

Sources and further reading