Quick answer
OpenAI's September 25 update adds Security history in ChatGPT: a record of recent sign-ins, sign-outs, and changes to account security settings. On the web, open Settings → Security and login → Security history. It helps you review past events; Active sessions is the separate place to manage current sessions. This explainer is based on official documentation, not a live-account test.
Where to find Security history
In ChatGPT on the web, open Settings, choose Security and login, then select Security history. Review the event time alongside the device and location details. OpenAI cautions that some details can be approximate or missing.
Sources: OpenAI
Past events and active sessions answer different questions
Security history records events such as password changes and changes to multi-factor authentication (MFA) or passkeys. Active sessions instead helps you inspect and end current sessions; it does not list recently signed-out sessions.
- Active sessions does not show or manage connected apps, third-party app sessions, third-party-only Sign in with ChatGPT sessions, or Codex CLI sessions.
- OpenAI excludes accounts linked to an organization's SSO sign-in from Active sessions. That documented restriction should not be assumed to describe the new Security history feature.
- Logging out of all sessions includes your current session and can take up to 30 minutes.
What to do with an event you did not authorize
OpenAI recommends changing an exposed password if you use one, logging out of all sessions, keeping relevant activity details, and contacting OpenAI Support. API users should also delete compromised keys and check usage. Support is available through the chat on OpenAI's Help Center.
Sources: OpenAI
Check the app's own controls before sharing sensitive material
This is a ChatGPT account feature, not a Chat AI feature announcement. When considering Chat AI, read its own privacy overview and linked platform policies: prompts and relevant context are processed by AppZone services and selected AI providers. A shared model provider does not establish shared account controls.
- Review Chat AI data flows and privacy policies
- Compare multi-model apps beyond model names
- Read the separate ChatGPT Privacy Center explainer
Sources: Chat AI
Frequently asked questions
What readers usually ask
Does an unfamiliar location prove someone accessed my account?
Not by itself: OpenAI says location and device details may be approximate or unavailable. Review the event and time together, and follow its account-security guidance for activity you did not authorize.
Will Active sessions show every app connected to ChatGPT?
No. OpenAI explicitly excludes connected apps and third-party sessions from that view. Do not use an empty session list as proof that no external service has access.
Can I use Security history to sign out another device?
Use Active sessions for session-management controls. Security history is the record of past security events.
Evidence
Sources
- September 25 ChatGPT Security history announcementOpenAI · Primary source
- Review security history and respond to unauthorized accessOpenAI · Primary source
- Active sessions: scope, exclusions, and sign-out controlsOpenAI · Primary source
- Chat AI privacy overview and platform-specific policiesChat AI · Primary source