WayToClawEarn
High impactThe Verge / Emma Roth

OpenAI launches advanced account security: Passkey and physical security key escort ChatGPT and Codex users

OpenAI today launched Advanced Account Security, which supports pass keys and physical security keys to log in to ChatGPT and Codex, and automatically exits AI model training. This is OpenAI’s strongest account security feature yet.

WayToClawEarn EditorialPublished May 1, 2026Updated Aug 8, 2026

Editorial review of public sources · AI-assisted drafting. How we work · Original source

Core conclusion

OpenAI officially launched "Advanced Account Security" on May 1, 2026, which is open to users with high security risks. Once enabled, users can log in to ChatGPT and Codex accounts through Passkey or physical security keys, while receiving real-time alerts for new logins and automatically exiting AI model training. This is OpenAI’s most powerful update to date in the area of ​​account security, and is a direct response to growing concerns about account hijacking among users of AI tools.

Key Points

  • Time of incident: 2026-05-01 -Affected objects: All ChatGPT and Codex users, especially content creators who frequently use AI Agent
  • Core changes: Passkey login + physical security key + new login alert + automatic exit from training

Background and trigger events

AI account security is becoming a seriously underestimated risk point. As AI tools such as ChatGPT, Claude Code, and Codex are deeply embedded in the daily work of content creators and software developers, the consequences of account hijacking have become increasingly serious—not only involving API key leaks and fee theft, but also more subtle threats such as prompt word history exposure and automated work order data leakage.

The advanced account security features launched by OpenAI were confirmed by a report by The Verge reporter Emma Roth on May 1, 2026. Users can turn on "Advanced Account Security Settings" in the OpenAI account settings. Afterwards, they can only log in by binding a passkey or a physical security key (such as YubiKey). The traditional password + SMS verification code method is completely replaced.

Key Impact (by Dimension)

DimensionsChangeWhat it means to usRecommended actions
Login securitySupports Passkey and physical security keysCompletely eliminates phishing attacks and SIM Swap risksBind security keys to ChatGPT and Codex accounts instantly
Account AlertsAutomatically send notifications for new loginsDetect abnormal login behavior in timePay attention to email/App notifications after opening
Model trainingAutomatically exit training data after enablingNo need to manually fill in the opt-out formPrivacy-sensitive users must enable
Development processCodex account synchronization protectionAutomated workflow API is more secureConfirm the key rotation mechanism in CI/CD

Adaptation suggestions

  • If you use YubiKey or Google Titan, you can now bind it directly in the OpenAI account settings, instead of relying on third-party 2FA tools before
  • For team collaboration scenarios, it is recommended to enable this function for each core member to avoid the risk of leakage caused by shared passwords
  • API calls in automated workflows are not affected (API uses API Key authentication), but it is recommended to check the API Key permission scope simultaneously
  • When enabled, ChatGPT's web session will require security key verification every time a new device logs in

Task List

  • Log in to your OpenAI account, enter security settings, and turn on Advanced Account Security
  • Bind 1 Passkey (supported by mobile phone/computer) + 1 physical security key (spare)
  • Check whether Codex and ChatGPT accounts are enabled simultaneously
  • Clean up API Keys that are no longer used

Example: How to enable advanced security in OpenAI

terminal
 ChatGPT
1. → Settings
2. Security & Data
3. Advanced Account Security → Enable
4. Passkey (Face ID / Touch ID / Windows Hello)
5. YubiKey
6. 。。

OpenAI

ChatGPT , OpenAIChatGPTClaudeCodexn8n , API Key Web 。Hermes Agent It is also recommended to enable strong authentication.

Internal link guidance

View source →

Disclaimer: this site shares educational insights only, for inspiration and reference. No outcome guarantee; external execution and decisions are your own responsibility.