OpenAI Adds Smartphone Passkeys and Custom YubiKeys for ChatGPT Account Protection

Stylized illustration of a brain with radiating lines and dots, representing the concept of artificial intelligence or neural networks.

OpenAI has launched an Advanced Account Security program that lets ChatGPT users protect their accounts with smartphone passkeys and hardware security keys, replacing password-and-OTP sign-in with phishing-resistant credentials anchored either in a phone or in a physical key. Yubico said it is working with OpenAI on custom YubiKeys designed for OpenAI users, giving high-risk account holders a portable hardware authenticator that travels with them.

For most users, the new option is the smartphone passkey. Registering a passkey through ChatGPT account settings binds the credential to the device and unlocks it with the phone’s built-in biometric, Face ID on iPhone or fingerprint on Android, eliminating the need to type a password or accept a text-message code that can be intercepted through SIM-swap fraud. Because ChatGPT is heavily used on its mobile app, the passkey workflow effectively becomes the default sign-in path for users moving between phone and desktop sessions.

OpenAI framed the program as a stronger option for users who face targeted phishing risks, including journalists, researchers, public figures, developers, and organizations managing sensitive AI workflows. Account takeover on an AI platform can expose chat history, API usage, proprietary prompts, uploaded files, and connected automation, making mobile-first authentication a meaningful security control rather than just a consumer convenience feature.

The release also connects to the wider problem of identity in AI-driven activity. VeryAI recently launched a palm biometrics platform for AI agent identity, and Proof joined the FIDO Alliance to work on identity standards for AI agents. OpenAI’s update covers the user side of that ecosystem: the question of who is actually behind the device controlling an AI account.

Passkeys rely on public-key cryptography, with the private key never leaving the user’s device, so a phishing site cannot trick the device into releasing it. Hardware security keys offer the same model in a separate physical authenticator that plugs into a USB port or taps via NFC against a phone. Both approaches are particularly relevant for AI services because account credentials can unlock not only a chat interface but also APIs, stored files, and automation tied to a paid plan.

OpenAI’s help documentation advises users to register more than one passkey or hardware key, reducing the risk of being locked out if a phone is lost. That guidance reflects a recurring lesson from mobile passkey deployments: device migration and loss are now central to the authentication design, not edge cases.

Sources: OpenAI, OpenAI Help, Yubico

By the Mobile ID World Editorial Team