Vol. 1 · Edition 033Free · No paywall

Everyone Needs a Samwise

AI news · Synthesized · Opinionated · 🌿

6
Launch partners for Sign in with ChatGPT
Airtable · GitLab · HubSpot · Notion · Supabase · Vercel
Product
By Sam Taylor with Samwise

On six launch partners, what name, email, and profile picture actually reveal, and why becoming a login provider is a bigger ambition than building a better chatbot

OpenAI became an identity provider last week. The footnote is worth reading.

Source lean on this story
▲ avg

Anti-AI

00

Skeptic

02

Neutral

00

Pro (practical)

00

Pro (hyped)

01

← Anti-AI · Pro-AI →

If you've signed up for anything online in the last five years, you've seen the row of buttons. "Continue with Google." "Sign in with Apple." Maybe Microsoft. You click one, get sent to a familiar page, click approve, you're in — no new password, no email confirmation loop. That row just got a new addition.

OpenAI launched "Sign in with ChatGPT" on August 2, as a live beta. Six launch partners: Airtable, GitLab, HubSpot, Notion, Supabase, and Vercel. The flow is exactly what you'd expect — click the button on a supported app, authenticate with your ChatGPT account, approve what gets shared. The partner app receives three things: your name, your email address, and your profile picture.

That's it. Except that's not quite all that happens.

3
Pieces of data shared with the app when you click Sign in with ChatGPT: name, email, profile picture

→ Source: OpenAI Help — Sign in with ChatGPT

What's actually going on

Here's the object lesson. When you sign in to Notion with your Google account, Google learns that you use Notion. That sounds trivial — it isn't. Over time, Google builds a picture of which apps you use, which devices you sign in from, how often, and from where. This is called the login graph, and it's one of the reasons Google's identity business is valuable. Not just because it's convenient, but because it adds context to everything else Google already knows about you.

"Sign in with ChatGPT" creates the same structure. OpenAI now learns which apps you connect to via your ChatGPT login. A Notion user who signs in with ChatGPT is a different kind of person than a GitLab user who does the same. ChatGPT already knows your conversations. Now it knows your software footprint.

That combination — what you've asked an AI, and which apps you use — is meaningful data. Not necessarily misused, but meaningful.

'Sign in with' providers — what each one already knows about you
ProviderWhat they already hadWhat they gain when you use their login
GoogleEmail, search history, Drive, Maps locationWhich third-party apps and services you use
AppleApple ID, device usage, App Store purchasesWhich apps you connect — with a throwaway email option
MicrosoftMicrosoft account, Office files, LinkedIn (many users)Which apps you sign in to
ChatGPT (new)Your conversations with an AI assistantYour software footprint — which apps you link

The footnote I mentioned

Before deciding how much to trust OpenAI with your login, there's one thing worth knowing. A class action filed May 13, 2026 alleges that OpenAI embedded Facebook Pixel and Google Analytics tracking code inside ChatGPT, silently transmitting user account identifiers and email addresses to Meta and Google without adequate disclosure. OpenAI has not publicly responded to the allegations. The case has not been adjudicated.

I'm not saying this makes "Sign in with ChatGPT" unsafe. I'm saying: if your assumption going in is "OpenAI is careful and private with my data," the full picture is more complicated than that. This launched eight weeks after that case was filed.

Source spread

What's real / What deserves a side-eye

What's real:

  • This is genuinely convenient. If you already have a ChatGPT account, you don't need a new password or a new email verification on any of the six launch platforms. That's a real quality-of-life improvement.
  • The underlying technology — OAuth 2.0 and OIDC (a standard for verifying identity, the same one Google and Apple use) — is well-understood and auditable. OpenAI didn't invent a new pipe; they plugged into an existing standard.
  • Enterprise administrators get real controls: disable Sign in with ChatGPT across the whole organization, or restrict it to an approved list of apps. That's a useful governance lever for anyone managing a workplace deployment.

What deserves a side-eye:

  • "Your login activity" is contextual data even when the token itself is minimal. OpenAI knowing you log in to Airtable, HubSpot, and Vercel tells them you're probably running a startup or product team. That's useful signal to have about a user, and it's accurate to name it.
  • The pending class action about tracking pixels changes the trust calculation slightly. Not conclusively — the case hasn't been decided — but "we didn't tell you we were sharing your data with Meta and Google" and "trust us with your login" are harder to reconcile.
  • Six partners is a small beta. The full list of places you can actually use this is short right now. The interesting question is how fast it expands, and whether the next wave of partners includes anything involving sensitive personal or financial data.

What to do about it

  • Check if you already use any of the six launch partners. Airtable, GitLab, HubSpot, Notion, Supabase, Vercel. If you use any of these, you may already see the "Sign in with ChatGPT" button as an option when creating or connecting accounts.
  • For low-stakes apps, the convenience is real. If you're setting up a Supabase account for a side project, using ChatGPT login is probably fine. The data stakes are low and the saved password hassle is real.
  • Hold off on sensitive work accounts. Linking your ChatGPT identity to apps that handle sensitive client data, medical records, or financial information is a different calculation. The class action context matters there.
  • If you manage a workplace ChatGPT deployment, configure the admin controls. Enterprise admins can disable Sign in with ChatGPT org-wide or restrict it to approved apps. Worth setting before employees start connecting company accounts without coordination.
  • Follow the expansion. The six-partner launch list is small. The risk profile changes as more apps — especially ones outside developer tools — start offering this option. Revisit this decision when the list grows.

Further reading

🌿

Liked this? Get the weekly digest.

Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.

Your take

How'd I do on this one?

What did I miss?

Tell Samwise (and Sam).

Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.