ChatGPT Sites: owner can manage an owner-only site but cannot visit its deployed URL

Open 💬 2 comments Opened Jul 30, 2026 by cezaronx

What issue are you seeing?

A user can fully manage a private ChatGPT Site—see it in the Sites library, edit it, and view analytics—yet the deployed URL returns "You do not have permissions to visit this site" after the user signs in.

The site is configured as Only you, and the user shown as its owner in Share settings is the same user who has management access. This makes the site unusable even for its owner.

What steps can reproduce the bug?

  1. Create and deploy a ChatGPT Site.
  2. Leave its audience set to Only you.
  3. Confirm the site is present in the Sites library and that the user can edit it and access its analytics.
  4. Use Visit, or open the deployed chatgpt.site URL while signed in as that user.

What is the expected behavior?

The user who owns and administers an Only you site should be able to open its deployed URL after signing in. If access depends on a distinct identity principal, the product should either recognize linked sign-in identities or show an actionable explanation and recovery path.

Additional information

The account UI displays two different email labels across the account menu and the Site owner field. The user reports they are linked sign-in identities for the same OpenAI account. That is a possible diagnostic lead only; this report does not claim it is the root cause.

No email addresses, site URL, project identifiers, or screenshots are included here. They can be provided through a private support channel if needed.

Related issues:

  • openai/codex#34985 — Site access denied on a deployed custom domain.
  • openai/codex#36126 — owner cannot change a deployed site from owner-only to public.
  • openai/codex#33280 — Windows Sites access-update and authentication fallback failure.

Those reports show a related Sites access/sharing cluster, but this report concerns the owner being unable to open an owner-only deployment itself.

Please investigate the identity principal used for private deployment access, reconcile it with the Sites ownership principal, and provide a recovery path for affected owners.

View original on GitHub ↗

2 Comments

seandearnaley · 20 days ago

I also have this problem, I think it may be related my older oauth outlook.com account signup, cant set a password either

jade-oai · 17 days ago

I'm running into this problem after changing the primary domain on my personal Google Apps for Domains/Google Workspace instance.