Skip to content
Performance & Accessibility

A Practical Guide to Accessible Authentication

WCAG 2.2 requirements that sign-in should not depend on remembering or transcribing information.

Marcus Adeyemi Technical Director 2 min read 20 views
A Practical Guide to Accessible Authentication

The key figures

Success Criterion 3.3.8
requires an alternative to cognitive function tests at Level AA
Password managers
copy and paste support is part of the solution
Object recognition
recognizing common objects is allowed
Personal content
recognizing content the user provided is allowed

Why this is worth getting right

Puzzles, memory tests and code retyping exclude people with cognitive disabilities, and WCAG 2.2 added criteria about it.

Do this, not that

Do

  • Allow paste and autofill in all fields
  • Offer alternatives to puzzle-based verification
  • Support passkeys or email links
  • Avoid retyping codes where autofill works
  • Test sign-in with assistive technology

Don’t

  • Blocking paste in password fields
  • Puzzle CAPTCHAs as the only option
  • Timed code entry with short limits
  • Memory-based security questions

When to bring in help

Our advice Bring in help when sign-in must meet WCAG 2.2.

Where this comes from

The figures and practices above come from the sources listed.

Working on something like this?

We take on Performance & Accessibility work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.

Where to go next

Spotted something wrong? Report an error on this page. We correct on the page and say what changed.

All services

The work behind this article, and what it costs.

Marcus Adeyemi

Builds and maintains the web work. Writes about front-end architecture, performance, accessibility and the unglamorous parts of keeping a site alive.

Keep reading

More in Performance & Accessibility