Overview
ChatGPT Work Cloud Browser is OpenAI’s user-triggered remote browser for supported public-web tasks.
OpenAI does not document a fixed crawler User-Agent for this identity. Instead, Cloud Browser signs outbound HTTP requests using Web Bot Auth / HTTP Message Signatures. Authentic requests include a Signature-Agent value of https://chatgpt.com, with public verification keys published by OpenAI.
Do not authenticate this traffic from a copied user-agent string alone. Verify the message signature and current OpenAI key material.
Identity
- Aliases
- ChatGPT Agent; chatgpt-agent; ChatGPT Operator; chatgpt-operator; Signature-Agent: https://chatgpt.com
- HTTP Agent Examples
-
No fixed HTTP User-Agent published; verify HTTP Message Signatures with `Signature-Agent: https://chatgpt.com`. - Identity Type
- HTTP message signature
- Evidence Method
- Validate the HTTP Message Signature / Web Bot Auth signature and confirm `Signature-Agent: https://chatgpt.com` against OpenAI’s current public key directory.
Classification
- Type
- AI
- Kind
- Agent
- Family
- ChatGPT agent
- Purpose
- Authenticated user-triggered browser
Behavior and handling
- Common Use
- User-triggered public-web navigation and supported browser actions initiated through ChatGPT Work.
- Detection Notes
- Identify current Cloud Browser traffic by its signed request identity. The strings `chatgpt-agent` and `chatgpt-operator` may appear in provider-side labels or historical detection data, but they are not a substitute for signature validation.
- Respects robots.txt
- Depends
- Spoofing Risk
- Low when the HTTP message signature is validated against OpenAI’s current key directory; unauthenticated copied labels or headers are not trustworthy.
- Risk
- Neutral
- Recommended Handling
- Depends
Rules and controls
- Robots.txt Snippet
-
# No fixed robots.txt token is documented. Use authenticated request verification and access-control policy for signed Cloud Browser traffic.
Relationships
- Operator
- OpenAI Checked 2026-08-07
Relationships without an Evidence link are normalized from the canonical directory record. They should not be interpreted as independent proof of physical presence or request origin.