ChatGPT adds a security history page for sign-ins and account changes

ChatGPT's new Security history page shows recent sign-ins, sign-outs and security-setting changes, with event details that may be approximate.

Cole Walker

ChatGPT now has a security history page that lets users review recent account-security events in one place. OpenAI added the feature on September 25, covering events such as sign-ins, sign-outs, password changes and changes to multi-factor authentication, passkeys and other security settings.

On the web, the page lives under Settings, then Security and login, then Security history. OpenAI says individual events can include the time, location and device details, although some of that information may be approximate or unavailable.

The feature is useful because it answers a specific question: what security-related activity has recently happened on this account? It is not the same thing as an automatic fraud detector, and it does not replace the controls used to secure an account.

Security history is an audit trail, not an alarm system

OpenAI's account-security guidance separates Security history from Active sessions. Security history is for looking back at events. Active sessions is where users can review current sessions and sign out of them.

That difference matters when something looks unfamiliar. A location shown in an event may be approximate, and a device label may not contain enough detail to identify a session with certainty. The history can provide a useful clue, but one unusual entry should be checked alongside the event time, device information and the user's own recent activity.

OpenAI's guidance says that if activity appears unauthorised, users should secure the account rather than merely watching the history page. Recommended steps include changing an exposed or reused password, enabling multi-factor authentication and reviewing active sessions. Users can also log out of all sessions.

Security history therefore works best as a visibility tool. It can make account changes easier to spot after the fact, but prevention still depends on the underlying security settings and the way credentials are protected.

The page covers more than sign-ins

The release notes specifically list sign-ins and sign-outs, changes to MFA, passkeys and other security settings. OpenAI's security guide also lists password changes among the events that may appear.

That wider scope is important. A compromised account is not only a problem when somebody signs in. Changes to authentication methods or security configuration can matter just as much, especially if they make it harder for the real account owner to regain control.

For users who already check email notifications or password-manager alerts, the new page adds another place to reconstruct what happened. It also keeps security review inside the ChatGPT settings flow instead of forcing people to piece together several separate pages.

There are still limits. OpenAI does not say that every event will contain exact location data, and the release notes explicitly warn that some details may be approximate or unavailable. Security history should therefore be read as account telemetry, not perfect forensic evidence.

The useful takeaway is straightforward: if you want to review recent sign-ins or security-setting changes, ChatGPT now exposes that history directly on the web. If you find something you do not recognise, use the separate session and account-security controls to respond rather than assuming the history page has already taken action for you.

Sources

More from Xarmo News