Skip to content

Orion bug: ChatGPT/OpenAI login + 2FA fail even with Compatibility Mode #992

@0xnikr

Description

@0xnikr

Bug report / routing request

I am reporting a serious Orion browser compatibility bug that makes ChatGPT/OpenAI effectively unusable while trying to sign in.

I know the preferred product-bug route is OrionFeedback.org. I attempted to submit there, I wanted to also route this through Kagi's official GitHub org/repo so the team has another copy and can forward/triage it appropriately.

Summary

Users trying to use ChatGPT/OpenAI in Orion cannot reliably log in. Even after enabling Compatibility Mode for every ChatGPT/OpenAI page/URL involved and retrying the full sign-in flow, OpenAI’s login/2FA flow fails.

Observed behavior

  1. Open ChatGPT/OpenAI in Orion.
  2. Attempt to sign in.
  3. User has to enable Compatibility Mode for ChatGPT/OpenAI pages/slugs/URLs.
  4. Retry sign-in.
  5. Enter email and password successfully.
  6. Complete or attempt 2FA.
  7. OpenAI shows a red error: “This option is temporarily unavailable.”
  8. Trying another 2FA option, such as push notification or email, produces the same red error.
  9. Result: the user cannot complete login and cannot use ChatGPT signed in through Orion- even IF they successfully enter the correct 2FA code from whichever channel.

*Important details

  • Happens in regular browsing mode.
  • Happens in private browsing mode.
  • Happens even after Compatibility Mode is enabled for OpenAI/ChatGPT pages.
  • The failure appears specifically around OpenAI’s auth/2FA flow rejecting something about Orion’s browser/session behavior.
  • This is not just a minor rendering issue; it blocks access to ChatGPT entirely for affected users.

*Expected behavior

ChatGPT/OpenAI login should work in Orion without users having to manually enable Compatibility Mode across multiple OpenAI/ChatGPT URLs, and 2FA options should complete normally.

*Impact

This makes Orion unusable for ChatGPT users who need to sign in, despite ChatGPT being one of the most important web apps people use daily.

*Requested investigation areas

Please investigate Orion’s compatibility with OpenAI/Auth0/ChatGPT login and 2FA flows, especially:

  • cookies/session state
  • fingerprinting/privacy protections
  • Compatibility Mode inheritance across OpenAI/Auth0/ChatGPT subdomains
  • storage isolation
  • user agent/client hints
  • popup/redirect behavior
  • anti-fingerprinting behavior that could cause OpenAI to reject 2FA options

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions