WCAG 3.3.8 · Level AA · WCAG 2.2
Accessible Authentication (Minimum)
Authentication must not rely on cognitive function tests (memorising passwords, solving puzzles) unless an alternative or mechanism exists.
- Principle
- Understandable
- Guideline
- Input Assistance
- Level
- AA
- Added in
- WCAG 2.2
What it means
Authentication must not rely on cognitive function tests (memorising passwords, solving puzzles) unless an alternative or mechanism exists.
This is the short summary — a long-form breakdown (with code examples, common failures, and fix patterns) is queued for this criterion. In the meantime, the official W3C document linked at the end of the page is the authoritative source.
Quick checks
- Run axe DevTools against the page and filter for rules citing 3.3.8.
- Navigate the component with Tab + Enter only and confirm nothing is orphaned.
- Inspect the accessibility tree in DevTools (Accessibility pane in Chrome/Firefox).
Further reading
The authoritative source is the official W3C Understanding document for 3.3.8. Framework-specific patterns and axe-rule mappings land here as the library grows.