Designing Better Mobile User Authentication

Designing Better Mobile User Authentication

Author: JVDS Design Studio Reading time: about 4 min
Link copied

Reduce the Friction of Registration and Login


User authentication is often treated as an afterthought. We expect it to work but rarely examine it closely. It should be simple, yet in practice it can create problems for users and the companies operating the product: failed logins, forgotten passwords, and lengthy interactions.

The login screen is one of the most frequently displayed UI designs in an application. According to the source, 75% of people have reset and abandoned a previous password while logging in. On corporate intranets, forgotten passwords are the leading daily issue handled by help desks. Clear language and a well-designed flow can substantially reduce these problems.

To improve the authentication experience, lower service costs, and increase conversion, consider the following areas.

State the Rules Clearly

Examples from Amazon and AliExpress

Avoid vague rules. Explain requirements clearly rather than waiting for a validation error to tell users that a password must contain at least six characters. A minimum length is useful, but the requirements should not become needlessly complex. A meaningful password is more useful than a random string of characters.

Show the Password


An Example from Amazon

Consider allowing users to reveal their password. This helps with both login and registration. Instead of requiring a second confirmation entry, provide a show-or-hide control in the password field so users can confirm the first entry. The control may be a small icon, a text label, or a checkbox. Amazon made a subtle variation by keeping masked characters in the field while displaying the full password below it. This builds confidence, reduces anxiety, and signals that the password is being handled appropriately.

Handling Forgotten Passwords

Slack and Trello Examples

No one wants to reset a password unless login has failed or an account has been compromised. How can users sign in without resetting it? Send a short link that enables direct login without a reset. Tip: Use microcopy effectively while keeping it consistent with the product's overall voice.

Passwordless Login

Medium and App Store Examples

Passwords are always troublesome, so another option is to remove them altogether. Use an external authentication method, such as a social-media account, or biometric recognition. Purchases in the App Store, for example, have used fingerprint authentication.

Two-Step Verification

Sometimes an additional layer of security is appropriate. Make sure users are not repeatedly interrupted for a period of time. Treat it as an extra measure without burdening people in the name of protecting them. Tip: If you want users to enable two-step verification, consider an incentive—Mailchimp offered a 10% discount to accounts that enabled it.

Mobile Login

Mailchimp and Instagram Examples

Although the principles above apply across devices, mobile devices offer additional options. If you know that a user is on a phone, you can send a text message or push notification that quickly takes them to the intended destination inside the APP.

PIN Codes and Numeric Passcodes

iOS Lock Screen Example

When a full password is unnecessary, use a numeric passcode entered through a number pad.

Other Authentication Methods

Android Lock Screen Example

Other forms of authentication are also available, such as drawing a pattern by connecting points on a grid or tapping a specific area of the screen.

Ask for a Username Only When Necessary

If an account system is required, consider using an email address. Do not request a separate username solely for authentication. Even on community sites, users may sign in with a Twitter or Facebook account.

Whatever method you choose, consider the context of use. Require the least possible effort, avoid unnecessary complexity, and make authentication feel as frictionless as possible.

从想法到落地,我们一起完成

以用户体验为核心,打造真正可用、可增长的数字产品

和我谈谈您的项目