ChatGPT Security History: Check Logins and Secure Your Account

Quick answer: ChatGPT now has a Security history page that shows recent sign-ins, sign-outs, and changes to passwords, multi-factor authentication (MFA), passkeys and other security settings. On the web, open Settings → Security and login → Security history. Review the event time, approximate location and device details. If anything looks unfamiliar, change your password, end active sessions, review sign-in methods and contact OpenAI Support.[1][2]

Two-minute account check

  1. Open Settings → Security and login → Security history.
  2. Check every recent sign-in, sign-out and security-setting change.
  3. Compare the time, location and device with your own activity.
  4. Open Active sessions and remove devices you do not recognize.
  5. If you suspect access, change your password and use Log out of all sessions.
  6. Enable MFA after removing unauthorized access.

What ChatGPT Security History shows

OpenAI announced Security history on September 25, 2026 as a new way to review recent security activity on an OpenAI account. The log can include:

  • Account sign-ins and sign-outs
  • Password changes
  • Changes to multi-factor authentication
  • Passkey changes
  • Other security-setting changes
  • The event time, approximate location and available device details

OpenAI warns that location or device details can be approximate or unavailable, so one odd-looking field is not proof of account theft. Compare the complete event—time, device, action and location—with your own activity before deciding what happened.[2]

How to open ChatGPT Security History

  1. Sign in to ChatGPT on the web.
  2. Open your account menu and select Settings.
  3. Select Security and login.
  4. Select Security history.
  5. Review each event type, time, location and device entry.

The official navigation path currently applies to ChatGPT on the web. If the option is missing, confirm you are using the web interface and check again later rather than trusting a third-party “security history” page with your login.[1]

Security History vs Active Sessions

These pages answer different questions. Security history is an event log: it helps you understand what recently happened. Active sessions is a session-management page: it helps you see and end sessions that are still active.

Tool Use it to Important limitation
Security history Review recent sign-ins, sign-outs and security-setting changes Location and device details may be approximate or missing
Active sessions Review current browser and first-party OpenAI app sessions, then log them out Does not show third-party app sessions, connected apps, Codex CLI sessions or recently signed-out sessions

An Active sessions row may show browser or device information, the first-party app context, approximate location, sign-in time, trusted-device status and whether it is your current session. OpenAI says the feature does not cover accounts linked to an organization’s SSO sign-in, including SAML or OIDC.[3]

What to do if you see an unfamiliar ChatGPT login

Do not spend hours trying to prove whether the location label is exact. If the event time, device or account change does not match anything you did, treat it as suspicious and contain access first.

1. Save the useful details

Record the event type, timestamp, displayed device and approximate location. Do not publicly post private account data or recovery information. These details may help when you contact support.

2. Change the password

If the account uses a password and it may have been exposed, reused or shared, change it immediately. Use a new password that is unique to OpenAI and store it in a password manager.[2]

3. End active sessions

Go to Settings → Security and login → Active sessions. You can log out an individual session, or choose Log out of all sessions when the account may be compromised. OpenAI says logging out every device can take up to 30 minutes and includes the current session.[3]

4. Review MFA, passkeys and sign-in methods

Check Security history for changes you did not make. Remove unfamiliar methods where the settings allow it, then enable MFA. OpenAI notes that simply enabling MFA does not cancel existing logins; when unauthorized access is suspected, change the password and log out sessions first.[2]

5. Protect API access separately

If you also use the OpenAI API, delete any key that may have been exposed and review API usage for unexpected activity. OpenAI recommends keeping keys in environment variables, never embedding them in mobile or browser-side apps, using separate keys by project, and monitoring spend.[2]

6. Contact OpenAI Support

Open a support chat from the OpenAI Help Center and report activity you did not perform or authorize. Include the useful event details you recorded, but never send a password, passkey, MFA code, recovery key or full API key.

How to read location and device details safely

  • Approximate location: an IP-based location can differ from your physical location, especially with mobile networks, corporate gateways, VPNs or relays.
  • Device label: browser and device detection can be incomplete; compare it with the time and action instead of judging the label alone.
  • Expected sign-outs: changing a password, ending a session or normal session expiry can explain sign-out events.
  • Unexpected security changes: an MFA, passkey or password change you did not make deserves immediate action even if the location looks familiar.

The first two cautions follow OpenAI’s warning that some location and device details may be approximate or unavailable. The checklist is designed to avoid both extremes: ignoring a real takeover and panicking over one imprecise label.[1]

Monthly ChatGPT security checklist

  • Review Security history for events you do not recognize.
  • Review Active sessions and remove old or unfamiliar devices.
  • Use a unique password and keep MFA enabled.
  • Verify passkeys and recovery methods are yours.
  • Inspect connected apps separately; Active sessions does not manage them.
  • For API accounts, check keys, usage and spend alerts.
  • Never enter credentials after following an unexpected email link; open ChatGPT directly.

Frequently asked questions

Where is Security History in ChatGPT?

On ChatGPT web, go to Settings → Security and login → Security history.[1]

What events does ChatGPT Security History show?

It can show recent sign-ins, sign-outs, password changes, and changes to MFA, passkeys and other security settings, along with available time, location and device details.[2]

Is a wrong location proof my ChatGPT account was hacked?

No. OpenAI says location and device details can be approximate or unavailable. Compare the time, device and event with your activity. If the action itself is unfamiliar, secure the account immediately.[1]

Does enabling MFA log out other devices?

No. OpenAI says enabling MFA does not cancel existing logins. If you suspect unauthorized access, change the password and log out active sessions before enabling MFA.[2]

How do I log out ChatGPT on every device?

Open Settings → Security and login → Active sessions, choose Log out of all sessions, then confirm Log out of all devices. OpenAI says completion may take up to 30 minutes.[3]

Does Active Sessions include Codex CLI and connected apps?

No. OpenAI says Active sessions does not show or manage third-party app sessions, connected apps, Sign in with ChatGPT sessions used only for third-party services, or Codex CLI sessions.[3]

Last checked: September 26, 2026. Menus and account availability can change as OpenAI updates ChatGPT.

Official sources

  1. OpenAI: ChatGPT release notes
  2. OpenAI: Keeping your OpenAI account secure
  3. OpenAI: Managing active sessions in ChatGPT


Leave a Comment

muddaser logo

Public Speaker, Softskills trainer and technology enthusiast

Contact

Muddaser Altaf

Social Address