Sign in with ChatGPT at work: identity and AI spend policy

This research library uses AI-assisted source research and drafting. Linked sources support product claims; analysis and proposed exercises are our interpretation. Unless an article documents a test and its results, do not read it as a hands-on review or an independently verified benchmark.
Sign in with ChatGPT lets people log in to other tools with their ChatGPT account and, on a personal Plus or Pro plan, let those tools run AI requests on that plan. OpenAI announced at DevDay 2026 that plan usage now works in 16 participating tools, including Devin, Notion, Vercel, T3, OpenClaw and Dactyl, and the help article describes the controls. For an engineering team, this is a policy question before it is a tooling question: whose identity signs in, whose plan pays, and which tools may see company code.
Identity is available globally. Plan usage is limited to Plus and Pro in participating tools.
What does Sign in with ChatGPT change for a team?
It removes two frictions that used to slow down tool adoption. People no longer need a new account for each tool, and they no longer need an API key to pay for the AI inside it.
When someone signs in, the tool receives their name, email address and profile picture. Plan usage is a second, separate permission. Once granted, eligible AI requests from that tool count toward the person's ChatGPT Work and Codex usage. No OpenAI API key is created or shared, and the tool gets no access to ChatGPT conversations or memories.
The side effect is that a developer can adopt a new coding agent in minutes, on a plan they pay for themselves, with no ticket to IT or finance. That speed is the benefit. It is also why a team needs a position on it.
Where does this create risk?
The account is the first question. Plan usage is documented for Plus and Pro, which are individual plans. The documentation we read describes no Business or Enterprise workspace control over which tools may use a plan. If your company provides ChatGPT through a workspace, check which account people are signing in with before assuming your admin settings apply.
Data flow is the second. Sign in with ChatGPT tells you what the tool receives from ChatGPT. It says nothing about what the tool does with your repository once connected. That remains governed by each vendor's own terms and by your existing approval process for developer tools.
Spend is the third. Usage comes out of the person's plan, and there is an optional setting to let apps use credits after the plan limit. That setting is off by default. If your company reimburses plans or credits, you are paying for tool usage without seeing it per tool.
Offboarding is the fourth. Connections live in the person's ChatGPT settings. When someone leaves, those connections sit in their account, not the company's, and any work that depended on them needs another owner.
Which controls exist today?
| Control | Where it lives | Default | Who holds it |
|---|---|---|---|
| Sign-in consent | Consent screen in the tool | Asked per tool | The individual |
| Use your ChatGPT plan | Separate consent screen | Asked per tool | The individual |
| Weekly limit per app | Settings > Usage, as a percentage of weekly plan usage | Not documented | The individual |
| Credits after plan limit | Allow other apps to use credits after reaching your usage limit | Off | The individual |
| Disconnect a tool | Settings > Security and login > Sign in with ChatGPT | Not applicable | The individual |
| Which tools may touch company code | Your developer tool approval process | Your policy | Engineering leadership |
The per-app limit is a cap, not a reserved share of the plan. Setting one tool to a share does not protect the rest for Codex or ChatGPT.
Every documented control in the table sits with the individual. The last row is the one your team owns.
A decision table for common situations
| Situation | Suggested stance | Who approves |
|---|---|---|
| Developer uses an approved tool on a personal plan for side work | Allowed, no company code | Nobody |
| Developer connects an approved coding agent to company repos | Allowed if the tool is on your approved list | Engineering lead |
| Developer connects a tool that is not yet reviewed | Not on company code until reviewed | Security or tool owner |
| Company reimburses a Plus or Pro plan | Agree per-app caps and keep the credits setting off | Budget owner |
| Team relies on one person's connected tool for shared work | Move it to an account the team controls | Engineering lead |
Adjust the stances to your own risk appetite. The point is to decide once, in writing, instead of per request.
A rollout checklist
- List the tools in the supported set that people already use or want to try.
- Mark each one approved, under review or not for company code, using your existing tool review.
- Decide which ChatGPT account people should sign in with for work.
- If you reimburse plans, ask for per-app caps and the credits setting left off.
- Add Sign in with ChatGPT connections to your offboarding checklist.
- Review the list of connected tools with the team each quarter.
The policy can fit on one page. Keep it next to your other agent rules, so people find it where they already look.
What should you measure?
Measure adoption and value as well as cost. Ask each developer to check Settings > Usage once a month and report the share each connected tool used. Record which tools people kept and which they disconnected, and why. Where a tool produces changes for review, track review effort and rework as you would for any agent, using our guide to measuring an AI workflow before scaling it.
If one tool keeps taking a large share without clear results, that is a reason to cap it, not to buy more usage.
Where does training fit?
Tool choice matters less than the working method around it. A developer who briefs, reviews and owns agent work well will do so in Codex, Claude Code, Cursor or any of the connected tools. Our free Delegate, Review, Own guide describes that method, and our AI training for teams practises it on your own code.
Write a checklist of approved tools and account rules this week, and share it before the next person connects a new agent.