AI Learn
OpenAI · Practical Tutorial

Use ChatGPT Work’s cloud browser safely on signed-in websites

Delegate a bounded browser workflow, sign in only when needed, inspect confirmation requests and take over for sensitive or unsupported steps.

Reviewed September 20, 2026Independent tutorialFeatures may vary
Not official support. AI Learn is an independent education site. Check the provider’s current documentation for plan-specific limits, pricing and feature availability.
Before you start

The cloud browser runs in a separate cloud computer and does not inherit your normal browser session. Treat it like a delegated remote browser: grant only the sites needed, never paste secrets into ordinary chat, and review consequential actions before they are submitted.

1. Describe the website, desired outcome and boundaries before navigation starts

State the exact website, goal and forbidden actions before navigation starts. A narrow instruction such as “compare three refundable fares but do not book” is safer and easier to review than “handle my trip.”

2. Approve access only to the sites that are necessary for the task

Limit browsing to the minimum set of domains needed for the task. If a page redirects to a new service, verify why it is needed before allowing the workflow to continue there.

3. Use the secure sign-in flow and complete two-factor authentication yourself

Complete passwords, passkeys and two-factor authentication yourself through the secure sign-in flow. Do not paste credentials, recovery codes or payment secrets into the conversation.

4. Watch for confirmation prompts before bookings, payments, submissions or account changes

At checkout, booking, submission or account-change screens, read the final values yourself: recipient, amount, dates, cancellation terms and irreversible effects. Treat this as a human approval gate, not a formality.

5. Review the final page, receipt or saved result and take over whenever the site or task becomes sensitive

After the action, verify the result on the destination site—confirmation page, reservation record, sent message or account state. Save the confirmation identifier when one exists so completion is independently provable.

Try this prompt

Use the cloud browser to [goal] on [site]. You may browse and fill non-sensitive fields. Stop before any purchase, booking confirmation, form submission, message send, account change or other consequential action and show me exactly what will happen. If login is required, pause for me to take over.

Common mistakes

Assuming the cloud browser already has your logins; auto-approving every website; letting the agent submit a high-impact action without review; typing passwords into chat; believing every site permits automated browsing.

Finish check

The browser task stayed inside the approved sites, sensitive authentication stayed under your control, and every consequential action had an explicit human review point.

开始之前

云端浏览器运行在独立的云端电脑里,不会自动继承你平时浏览器里的登录状态。把它当成一个被委托的远程浏览器:只允许必要网站,不要把密码等秘密直接发到普通聊天里,提交重要操作前必须复核。

1. 浏览前先写清网站、目标和操作边界

浏览开始前先写清“哪个网站、要完成什么、绝对不能做什么”。例如“比较 3 个可退款票价但不要预订”,比“帮我处理行程”更安全,也更容易复核。

2. 只批准这次任务真正需要访问的网站

只允许访问完成任务所需的最少域名。如果页面跳转到新的服务,先确认这个站点为什么必要,再让流程继续,避免任务在不知不觉中扩大权限范围。

3. 使用安全登录流程,双重验证由你本人完成

密码、Passkey 和两步验证应由你自己通过安全登录流程完成,不要把密码、恢复码、付款凭据等敏感认证信息粘贴进聊天。

4. 遇到预约、付款、提交资料或账户变更等动作时认真查看确认请求

遇到付款、预订、提交或账号修改页面时,由你亲自核对收款方、金额、日期、退款条款和不可逆影响。这一步是真正的人类审批点,不是走形式。

5. 最后检查页面、回执或保存结果;一旦任务变敏感或网站受限就主动接管

动作完成后回到目标网站验证结果,例如确认页、订单记录、已发送消息或账号状态。有确认编号时保存下来,让“是否完成”能够独立证明。

可以直接套用的提示词

使用云端浏览器在 [网站] 完成 [目标]。可以浏览并填写非敏感字段;在付款、确认预约、提交表单、发送消息、修改账户或任何有明显后果的操作前必须停下,并准确告诉我下一步会发生什么。如果需要登录,暂停让我接管。

常见错误

误以为云端浏览器已经继承你的登录;对所有网站一律自动批准;高影响操作不复核就提交;把密码发进聊天;默认所有网站都允许自动浏览。

完成检查

浏览任务始终限制在批准的网站内,敏感认证由你控制,所有有明显后果的动作都有明确的人工确认点。

開始之前

雲端瀏覽器執行在獨立的雲端電腦裡,不會自動繼承你平時瀏覽器裡的登錄狀態。把它當成一個被委託的遠程瀏覽器:只允許必要網站,不要把密碼等秘密直接發到普通聊天裡,提交重要操作前必須復核。

1. 瀏覽前先寫清網站、目標和操作邊界

瀏覽開始前先寫清“哪個網站、要完成甚麼、絕對不能做甚麼”。例如“比較 3 個可退款票價但不要預訂”,比“幫我處理行程”更安全,也更容易復核。

2. 只批准這次任務真正需要存取的網站

只允許訪問完成任務所需的最少域名。如果頁面跳轉到新的服務,先確認這個站點為甚麼必要,再讓流程繼續,避免任務在不知不覺中擴大權限範圍。

3. 使用安全登錄流程,雙重驗證由你本人完成

密碼、Passkey 和兩步驗證應由你自己通過安全登錄流程完成,不要把密碼、恢復碼、付款憑據等敏感認證資訊粘貼進聊天。

4. 遇到預約、付款、提交資料或賬戶變更等動作時認真查看確認請求

遇到付款、預訂、提交或賬號修改頁面時,由你親自核對收款方、金額、日期、退款條款和不可逆影響。這一步是真正的人類審批點,不是走形式。

5. 最後檢查頁面、回執或儲存結果;一旦任務變敏感或網站受限就主動接管

動作完成後回到目標網站驗證結果,例如確認頁、訂單記錄、已發送消息或賬號狀態。有確認編號時保存下來,讓“是否完成”能夠獨立證明。

可以直接套用的提示詞

使用雲端瀏覽器在 [網站] 完成 [目標]。可以瀏覽並填寫非敏感字段;在付款、確認預約、提交表單、發送消息、修改賬戶或任何有明顯後果的操作前必須停下,並準確告訴我下一步會發生甚麼。如果需要登錄,暫停讓我接管。

常見錯誤

誤以為雲端瀏覽器已經繼承你的登錄;對所有網站一律自動批准;高影響操作不復核就提交;把密碼發進聊天;預設所有網站都允許自動瀏覽。

完成檢查

瀏覽任務始終限制在批准的網站內,敏感認證由你控制,所有有明顯後果的動作都有明確的人工確認點。

Official references

Check current product details at the source

Related practical tutorials

Continue with another single-task workflow.

All tutorials →