Skip to content

OpenAI's __obi cookie ties ad pixels to ChatGPT accounts

OpenAI's ad pixel sets a one-year __obi cookie linking other sites to a ChatGPT account; scraped identity beat advertiser data 685 to 255.

By Tech AI Wire Team

4 min read

XLinkedIn
The 1515 Third Street office building in San Francisco, which was OpenAI's headquarters when the photo was taken in June 2025.
Photo: Coolcaesar

By the numbers

scraped vs advertiser-supplied identity events
685 to 255
how long the __obi cookie persists
1 year
sites where a postal code was captured
28

A security researcher has documented how OpenAI's advertising pixel connects a person's activity on ordinary shopping and booking sites back to their ChatGPT account. Jamie Larson of Buchodi Threat Intel published the analysis on September 20, 2026. It matters to developers because the mechanism runs on any site whose owner installed OpenAI's measurement pixel, and OpenAI's own documentation does not tell them to warn anyone.

A pixel is a small piece of JavaScript a site owner adds so an advertising platform can count which ads led to a sale. Meta and Google have offered them for years. OpenAI's version is newer, and it arrives alongside an ad business the company says is growing quickly.

What the pixel sends

At the center is a cookie named __obi, scoped to the .openai.com domain. According to Larson's analysis, it carries identity and browsing data from third-party sites back to OpenAI, and it lasts a year.

Two kinds of data travel with it. The first is personal information reduced to a SHA-256 hash, a one-way scramble that cannot be read back directly: email addresses, phone numbers and names. The second is location data sent in the clear, including country, region, city and postal code.

Larson's central finding is about where that identity data comes from. Some of it is handed over deliberately by the advertiser. The rest the pixel picks up itself from the page, including from form fields. In Larson's words, "scraped identity outnumbered advertiser-supplied identity 685 events to 255."

That ratio is the story. The pixel is collecting more about visitors on its own than the site owner is choosing to send.

Notebookcheck, summarizing the research on September 21, reports a postal code captured in 100 events across 28 sites, and behavior seen in Germany and 30 other European markets. It also reports that only about one in five ChatGPT sessions produced an identifier at all.

Where the cookie does and does not work

The tracking is not universal. Larson reports it working on Chrome for Android, and not on Apple's platforms.

BrowserAffected
Chrome for AndroidYes
SafariNo, blocked by Intelligent Tracking Prevention
Chrome on iOSNo, it runs on WebKit

Safari blocks it because Intelligent Tracking Prevention restricts cookies sent across sites. Chrome on iOS is unaffected for a different reason: Apple requires browsers there to use WebKit, so it inherits the same restriction.

One detail cuts against the worst reading. Because __obi is scoped to OpenAI's own domain, the advertisers running the pixel cannot read it themselves. The linkage is visible to OpenAI, not to the shop.

What OpenAI's own documentation says

OpenAI documents the measurement pixel publicly, and that documentation confirms the mechanism rather than contradicting it.

The docs describe a browser SDK that attributes website events to ChatGPT ads. Site owners load a script from bzrcdn.openai.com and add a Pixel ID from Ads Manager. The guidance is to place it early: "Put the script near the top of your <head> to ensure early conversions aren't lost while other content loads."

The documentation states that the pixel collects conversion events, hashed email, phone, name and location, and automatically detected customer information when advanced matching is switched on. It says raw personal information is not sent, only hashes.

It also documents an off switch. Calling oaiq("consent", false) before the pixel starts stops the measurement traffic, and the docs state that "when consent is false, the Pixel doesn't send measurement-event pings."

What the documentation does not do is tell site owners to obtain consent or notify visitors before deploying it. It describes the mechanism and leaves that decision unstated.

Larson reports putting questions to OpenAI about how the cookie is classified, and whether people who refuse marketing consent still receive it. Notebookcheck reports that OpenAI "left both of them unanswered."

What this means for developers

Check whether your site is running it. Search your codebase and tag manager for oaiq, for bzrcdn.openai.com, and for any script your marketing team added during an ad campaign. Pixels are frequently installed through a tag manager without a commit, so the repository alone is not proof of absence.

If it is there, the consent call is the control you have. Wire oaiq("consent", false) to your existing consent banner so the pixel stays silent until a visitor agrees, rather than relying on the default. Treat this as the same class of work as your Meta or Google pixel, not as something new.

Look hardest at advanced matching. That is the setting behind the scraped-identity figure, and it is the difference between sending a hashed email a customer gave you and having the page read one it finds. If your forms carry email addresses, phone numbers or postal codes, decide deliberately whether that feature should be on.

Hashing is not anonymization, and it is worth being clear with colleagues about that. A SHA-256 hash of an email address is the same value for everyone who hashes that address, so it works perfectly well as a join key across companies. It hides the text, not the person.

For teams in the EU and UK, this is a legal question as much as a technical one, and the cookie's classification is the crux. A cookie treated as analytics can be argued onto a different consent footing than one treated as marketing, which is precisely the question OpenAI has not answered. Until it does, the conservative reading is the defensible one. This follows OpenAI's steady expansion of the same ad system, including the Sponsored Agents pilot inside ChatGPT ads last week.

Sources

  1. ChatGPT now knows what you do on other websites via ad collector - Buchodi Threat Intel
  2. Measurement Pixel - Ads - OpenAI Developers
  3. ChatGPT's __obi cookie follows you to other websites - Notebookcheck

Related articles

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.