- Sources: researcher write-up, HN discussion
- Summary: The write-up names a single identifier,
__obi, set by bzr.openai.com, scoped to .openai.com with a Max-Age of one year and SameSite=None, and reports it bound to the ChatGPT account subject through a 60-second RS256 JWT. It states __obi is the only OpenAI identifier configured with SameSite=None and that every other OpenAI cookie was blocked on the same requests, and that OpenAI's own cookie policy classifies it as an Analytics cookie, so a visitor who grants analytics consent and refuses marketing consent still receives it. The browser attaches that one cookie to the script src request fetching the conversion pixel SDK before any OpenAI code runs, so the SDK's own no-credentials fetch path does not stop it, and the advertiser cannot read the value because it belongs to a domain their scripts cannot access. The author marks his own limits, namely that the observation is on Chrome for Android, that roughly one ChatGPT session in five produced a sync token, and that the server-side join to an account is inferred from the design rather than watched, and he states OpenAI Support acknowledged an inquiry sent 2026-09-14 and answered neither question. - Why it matters: One analytics-classified cookie resolves advertiser-page browsing to a ChatGPT identity, and the site operator who installed the pixel can neither read the value nor see that it was sent.
- Follow-up: Track whether OpenAI answers the two questions or documents what the ad collector identifier is joined to.
send feedback on this story