Understandable · Level AA · Introduced in WCAG 2.2
WCAG 3.3.8: Accessible Authentication (Minimum)
Published by whatisADA / Grow Wild Agency · Updated
What this criterion means
Authentication steps should not require an unassisted cognitive test unless a defined exception applies. Alternatives or assistance such as password-manager support and paste can remove memory and transcription barriers; AA also permits specified recognition exceptions.
A practical example
A sign-in form blocks pasting a one-time code and separates it into six fields. Allow the complete code to be pasted and correctly distributed or use one clearly labeled field, then test the full login and recovery process.
How to check it
- List cognitive tasks in sign-in, multifactor verification, account recovery and re-authentication.
- Test password managers, copy/paste and alternative authentication routes at each affected step.
- Check any claimed object-recognition or user-provided-content exception against the precise AA conditions.
What can be missed
Allowing paste in the password field does not establish that the recovery or verification step works. An inaccessible third-party challenge remains part of the user's authentication process.
Record your test
Use this worksheet to record what you actually checked. Notes stay on this device when you choose Save; they are not sent to us. Avoid personal or confidential information on shared devices.
These are your observations, not automated results or a conformance certificate. A complete evaluation needs appropriate scope, supported technologies, all applicable criteria and relevant page states.
Primary sources and scope
This is independent implementation guidance with original examples. The linked standard contains the full definitions, exceptions and conformance requirements. A criterion or checklist alone does not establish legal applicability or whole-site conformance.