Authorization scope
The service reads the sessionToken and account email from the official ChatGPT session-endpoint JSON to identify the subscription account, verify eligibility, and process the specified order. It does not require a browser profile, cookie list, localStorage, sessionStorage, or IndexedDB. After decryption, only the sessionToken enters the temporary vault. A login session can represent an authenticated identity and should only be submitted for an account you control.