A place to check what changed
OpenAI added Security history to ChatGPT on September 25. On the web, it is under Settings, then Security and login, then Security history. The list shows recent account events such as sign-ins, sign-outs and changes to a password, multi-factor authentication or passkeys.
For each event, OpenAI says the view can include a time, location and device details. Those clues can help a person decide whether an event looks familiar. They are not exact proof of where someone was: the company warns that some details may be approximate or unavailable.
A history is not a session switch
The distinction matters if you are worried about access right now. Security history describes past activity. Active sessions, a separate control under Security and login, is where OpenAI says you can review current sessions and sign out of them. Its guidance also provides a Log out of all sessions option. OpenAI says that can take up to 30 minutes to end other ChatGPT sessions.
A record of a sign-in does not tell you on its own whether that session remains open. Conversely, signing out does not explain how someone obtained access. The two views answer different questions, and neither replaces a unique password and a second sign-in factor.
What to do if something looks wrong
OpenAI's published advice is to change a password promptly if it may have been exposed, log out of all sessions and review the history for events you did not authorize. If the account also uses the OpenAI API, the company advises deleting potentially exposed API keys and checking usage for unexpected activity. It says to contact Support with details of the suspicious events.
There is a small but important order to this. OpenAI notes that enabling multi-factor authentication does not cancel existing logins. If you suspect an intruder is already signed in, changing a compromised password and ending sessions are separate steps from adding MFA. A strange location alone may be an imprecise signal; an account change you did not make is a stronger reason to act.
The useful boundary
This is a practical visibility change, not a claim that account takeovers are solved. OpenAI has not published a detection rate or a complete list of all events that will appear for every user. Availability may vary as the feature is introduced.
The sensible first use is simple: open the history, look for sign-ins or security-setting changes you cannot explain, then check Active sessions. If you find evidence of access you did not authorize, use OpenAI's recovery steps rather than relying on a location label alone.
Sources
- OpenAI: ChatGPT release notes, September 25, 2026Primary announcement of Security history, event fields and web navigation.
- OpenAI: Keeping your OpenAI account securePrimary guidance on reviewing history, active sessions, MFA and response to suspected unauthorized access.
- OpenAI: Managing active sessions in ChatGPTPrimary description of the separate current-session controls and their scope.



