Changes confirmed medium confidence

OpenAI Adds Security History to ChatGPT Accounts

Users can review sign-ins, sign-outs and changes to MFA, passkeys and other security settings from one account view.

Edited by Tyronne Panaino

OpenAI added Security History to ChatGPT on September 25, giving account holders a single view of recent access events and changes to important login protections. The feature covers sign-ins, sign-outs and updates to multi-factor authentication, passkeys and other security settings.

The change matters to anyone trying to understand whether an unfamiliar device or account-setting change deserves attention. Instead of relying only on memory or scattered notices, a user can inspect a dated activity record inside ChatGPT. OpenAI's announcement is the evidence for the feature; this run did not independently test rollout completeness, event accuracy or how quickly entries appear.

What the history records

The official ChatGPT release notes say each event can include its time, location and device details. OpenAI also cautions that some of those details may be approximate or unavailable. That qualification is important: the view can provide investigative context, but an incomplete location or device field should not be treated as a definitive account of who performed an action.

The listed event types span both access and configuration. Sign-ins and sign-outs can show when an account session changed, while entries for MFA, passkeys and other security settings can surface changes to the protections around future access. The release note does not claim that the history prevents unauthorized access; it is a review surface for recent activity.

Where users can find it

On the web, OpenAI directs users to Settings, then Security and login, then Security history. A practical review is to compare an unfamiliar entry with devices and account changes the user actually recognizes, then use the account's security controls if the activity cannot be explained. That is a recommended workflow, not evidence that every unexplained entry represents a compromise.

OpenAI's short announcement does not specify an event-retention period, an export format, a notification threshold or plan-by-plan and region-by-region rollout boundaries. Those are the next useful checkpoints for administrators and security-conscious users. Until OpenAI documents them, the supported conclusion is narrow: ChatGPT now offers a built-in record of the named access and security-setting events.

Status

Confirmed. OpenAI documents the feature and its navigation path. Internal confidence is medium because the evidence is a single first-party release note and this run found no independent test of availability, event completeness or metadata precision.

Sources

Update note: Last reviewed 2026-09-26. We will revise this post if OpenAI documents retention, export, notification or availability details.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.

More Changes coverage