Skip to main content
Ihr Browser ist zu alt, um diese Website korrekt anzuzeigen. Bitte aktualisieren Sie auf die neueste Version von Chrome, Edge, Firefox oder Safari.
Back to WCAG Database
Level AAWCAG 2.2

3.3.8 Accessible Authentication (Minimum)

A cognitive function test (such as remembering a password or solving a puzzle) is not required for any step in an authentication process unless that step provides an alternative.

Last reviewed: September 9, 2026

Understanding 3.3.8

The intent of this criterion is to ensure that people with cognitive disabilities can log in to websites. Forcing users to memorize and transcribe complex passwords or solve CAPTCHAs can be an insurmountable barrier for individuals with memory, reading, or processing differences.

How to Meet It

Do not block password managers from pasting into password fields. Support WebAuthn (biometrics/device PIN), OAuth (Log in with Google/Apple), or send magic links via email. If using a CAPTCHA, provide a non-cognitive alternative like an audio CAPTCHA (though audio CAPTCHAs are often poor experiences, alternative authentication methods are preferred).

Code Examples

INCORRECT
<input type="password" onpaste="return false;" /> <!-- Blocks password managers, failing 3.3.8 -->
CORRECT
<input type="password" autocomplete="current-password" /> <!-- Supports password managers -->

Frequently Asked Questions

Are passwords completely banned under WCAG 2.2?

No. You can still use passwords, but you cannot FORCE the user to memorize them. Allowing a password manager to autofill the password satisfies the requirement because the password manager handles the cognitive load.

Do traditional picture-based CAPTCHAs fail this criterion?

Yes, identifying objects in a picture is a cognitive function test. You must provide an alternative, such as support for third-party SSO (Log in with Google) or a hardware token.

Related Success Criteria

Quick Facts

  • Criterion3.3.8
  • LevelAA
  • IntroducedWCAG 2.2

Automate Compliance

AccessiSight automatically scans and identifies 3.3.8 issues in your codebase.

Try Scanner Free