Authentication flows that avoid cognitive function tests such as solving puzzles or memorizing passwords, and provide alternatives like copy/paste and password managers.
Accessible authentication refers to login and verification methods that don't rely on cognitive function tests like memorizing passwords, solving puzzles, or identifying distorted text (CAPTCHAs). These methods create barriers for users with cognitive disabilities, memory impairments, or other conditions that make traditional authentication challenging.
WCAG 2.1 Success Criterion 3.3.8 requires that websites provide accessible authentication alternatives. This doesn't mean eliminating security, but rather offering multiple pathways to authentication that accommodate different abilities and preferences.
Common accessible authentication methods include biometric authentication, hardware tokens, single sign-on (SSO), password managers, and authentication through trusted third parties. The key is providing options that don't require users to perform tasks that may be difficult due to their abilities.
Creating accessible authentication requires balancing security needs with user accessibility:
Multiple Options: Provide several authentication methods so users can choose what works best for their abilities and preferences.
Password Manager Support: Ensure compatibility with password managers and assistive technologies. Avoid custom input fields that interfere with auto-fill functionality.
Biometric Alternatives: Offer fingerprint, face recognition, or voice authentication where technically feasible and appropriate for the security level required.
Trusted Third Parties: Allow authentication through trusted services like Google, Microsoft, or Apple accounts that users may already have configured.
Hardware Tokens: Support hardware authentication devices for users who prefer or require physical authentication methods.
Clear Instructions: Provide clear, simple instructions for all authentication methods and offer help or alternative methods when users encounter difficulties.
Error Handling: Ensure error messages are clear and helpful, and provide ways to recover from authentication failures without starting over.
Join over 1 million websites using WebAbility to ensure digital accessibility compliance and provide equal access to all users.
The mental effort required to process information or complete a task. Interfaces should minimize unnecessary complexity.
A learning difference affecting reading and spelling. Designs benefit from clear typography, spacing, and predictable layouts.
Session time limits must warn users, allow extension, or be essential. Provide clear timers and recovery paths.
A neurodevelopmental condition affecting attention, hyperactivity, and impulse control. Interfaces benefit from clear focus management and minimal distractions.
This glossary is continuously improved and maintained by WebAbility to advance accessible design and development.Contact us to suggest improvements or report issues.