Account verification and security
Email checks, optional authenticator 2FA, and recovery.
Sign-in and email checks
Public accounts use a one-time email code to register and sign in. Login codes expire after 10 minutes, work only in the requesting browser, can be used once, and have attempt limits. Sign-in sessions last up to 12 hours. When an authenticator is enabled, an authenticator or unused recovery code is also required to sign in and perform sensitive actions. Staff tools always require authenticator protection. Keep access to your mailbox and recovery codes secure; no password is stored by the marketplace. The private staging site can continue to use ChatGPT sign-in.
Authenticator protection
You can add a time-based authenticator after email verification when the secure server configuration is connected. Once enabled, email verification alone cannot authorize sensitive actions. Time-based codes cannot be reused; save the one-time recovery codes shown at activation. Do not share the setup key or recovery codes.
Session controls
The additional verification uses a server-recorded, expiring browser cookie with HttpOnly and SameSite controls and Secure on HTTPS. Clear verification on all browsers from Security if needed, and also sign out of the primary account. Losing all recovery methods requires the final account-provider recovery process; support must not bypass identity verification.
Preview availability
Real email codes require a connected email provider and verified sender. Authenticator secrets require an encrypted server configuration. The interface reports unavailable configuration and does not claim a code was sent when delivery was not accepted by the provider. These services and production security review are launch prerequisites.