Optional Dispatch-Owned ChatGPT Sign-In
Import the ready-to-use helpers from app/chatgpt-auth.ts when the site needs optional or required ChatGPT sign-in:
- Use
getChatGPTUser()for optional signed-in UI. - Use the returned
userIdas the stable user key for user-owned records; do not use email as a durable identifier. - Use
requireChatGPTUser(returnTo)for server-rendered pages that should send anonymous visitors through Sign in with ChatGPT. - In a Server Component, start sign-in with
<a href={chatGPTSignInPath(returnTo)} target="_top">. The auth helper module is server-only; do not import it into a Client Component. - Do not use
fetch, XHR, a client-side router, or a framework link that can prefetch the sign-in route. SIWC must start as a top-level navigation. - Never request the AuthAPI authorization endpoint directly. The dispatch-owned
/signin-with-chatgptroute must start the SIWC flow. - Use
chatGPTSignOutPath(returnTo)for browser sign-out links or actions. - Pass a same-origin relative
returnTopath for the destination after sign-in or sign-out. The helper validates and safely encodes it. - Mark protected pages with
export const dynamic = "force-dynamic"because they depend on per-request identity headers.
Dispatch owns /signin-with-chatgpt, /signout-with-chatgpt, /callback, the OAuth cookies, and identity header injection. Do not implement app routes for those reserved paths. Routes that do not import and call the helper remain anonymous-compatible.
SIWC establishes identity only; it does not prove workspace membership. Use the Sites hosting platform's access policy controls for workspace-wide restrictions, or enforce explicit server-side membership or allowlist checks.
Use SIWC for account pages, user-specific dashboards, saved records, and write actions tied to the current ChatGPT user. Leave public content anonymous.
Source captured: 2026-10-11