targeted.gr

Login Friction: How Authentication Can Cost Brands Conversions

Login Friction How Authentication Can Cost Brands Conversions

A customer can want the product, trust the brand and be ready to buy — and still leave because they cannot remember a password.

That is the problem with login friction. Authentication usually exists for security, but from the customer’s perspective it is often simply another step between intention and action. Forgotten passwords, verification codes, account-creation requirements and failed sign-ins can interrupt a purchase before the customer reaches the part of the experience the brand actually wants them to see.

For Targeted.gr, this makes authentication more than a security issue. It becomes part of conversion optimisation and customer experience. If the login process is difficult enough, the brand can lose a customer before price, product quality or marketing even have the opportunity to matter.

Περιεχόμενα

Login Is Usually Not the Customer’s Goal

Very few people visit an e-commerce site because they want to authenticate themselves.

They want to buy something, track an order, manage a subscription, access a service or complete another task. The login screen is simply the gate they have to pass through first.

That distinction matters because customers evaluate friction differently depending on whether the step itself provides value. Filling in delivery information is understandable because the retailer needs to know where to send the order. Reconstructing a forgotten password can feel very different because the user experiences it as work created by the system rather than progress toward the purchase.

Baymard’s 2026 account and self-service UX research describes sign-in as a hurdle users need to overcome before reaching the task they actually care about, such as checkout, order tracking or returns. When that hurdle becomes difficult, frustration begins before the core customer experience has even started.

For marketers, that makes login friction unusually dangerous: it occurs before the brand has completed the conversion.

Forgotten Passwords Create Commercial Friction

The password problem is familiar because it appears small.

A user enters the wrong password.

They try again.

They select “Forgot password”.

They open their email.

They wait for the message.

They create another password.

They return to the original site.

Every individual step sounds manageable. Combined, however, they create a break in momentum.

Baymard’s usability research has found cases where password-reset problems contributed to checkout abandonment among existing-account users, with some tested sites seeing abandonment rates of up to 19% among those users when they struggled to regain access. The same research notes that overly complex password requirements can create problems not only during account creation but later, when users return and can no longer reproduce the credential they created.

That is the key conversion problem.

The customer did not abandon because the product was too expensive.

They abandoned because authentication became harder than completing the purchase felt worth.

Every Additional Step Competes With Purchase Intent

Digital conversion depends partly on momentum.

The user discovers a product, evaluates it, decides that they want it and moves toward action. Every additional interruption introduces another moment in which that intent can weaken.

Authentication can introduce several such interruptions:

a password the customer cannot remember,

an SMS code that does not arrive,

an authenticator app they need to locate,

an email verification flow,

a mandatory account-creation screen,

or an unfamiliar security prompt that creates uncertainty.

None of these automatically destroys conversion. In many contexts, stronger authentication is essential.

The marketing problem begins when the process asks for more effort than the level of risk or customer value reasonably requires.

A banking application and a low-value retail checkout clearly do not need identical authentication experiences.

Good CRO therefore does not mean removing security. It means matching the amount of friction to the context.

Mandatory Account Creation Can Interrupt the Checkout

One of the most obvious forms of login friction appears when a customer is asked to create an account before completing a purchase.

From the business perspective, account creation is attractive. It can support retention, loyalty, personalisation, order history and future marketing.

From the customer’s perspective, however, it may feel like an unrelated commitment introduced at exactly the wrong moment.

Baymard found that 42% of benchmarked sites in one study asked users to consider account creation before or during checkout, despite usability testing showing that this interruption can distract customers from their primary goal of completing the order. Its recommendation is to preserve guest checkout and, where possible, move optional account creation until after the purchase is complete.

The lesson for marketers is straightforward:

An account is valuable only if requiring it does not cost the transaction that would have created the customer in the first place.

Security and Conversion Are Not Opposites

There is a temptation to frame authentication as a trade-off.

More security means more friction.

Less friction means weaker protection.

Modern authentication technologies increasingly challenge that assumption.

Passkeys, for example, use public-key cryptography while allowing users to authenticate through familiar local methods such as fingerprint, facial recognition or device PIN. Instead of asking customers to remember another shared secret, the device proves possession of the credential.

That can improve both sides of the experience: stronger phishing resistance and fewer steps for the user.

The wider shift was explored in the Athens Pulse article “The Slow Death of the Password: Why Logging In Is Finally Changing” which looks at how passkeys and passwordless authentication are changing everyday digital behaviour.

For marketers, however, the significant point is different: better security can now become better UX rather than an additional obstacle layered on top of it.

Passkeys Can Improve Login Success

The commercial case for reducing authentication friction is becoming measurable.

The FIDO Alliance’s Passkey Index, based on organisations that have deployed passkeys, reported an average passkey login success rate of 93%, compared with 63% across the other authentication methods included in its dataset. It also reported substantially shorter average sign-in times for passkeys. These figures represent participating companies rather than every digital service, but they show why authentication is increasingly being treated as a product and conversion issue rather than simply a cybersecurity feature.

Individual implementations show the same direction.

Japanese marketplace Mercari reported that passkey authentication achieved an 82.5% success rate compared with 67.7% for SMS OTP in its implementation, while average authentication time fell from 17 seconds to 4.4 seconds.

A few seconds may sound insignificant.

At scale, those seconds sit directly inside a critical customer journey.

Faster Login Matters Most at High-Intent Moments

Not every login has equal commercial importance.

Authentication friction is especially important when it appears immediately before a high-intent action.

A customer opening a content account may tolerate an extra step.

A customer attempting to complete a limited-stock purchase may not.

The same applies to ticketing, travel booking, food delivery, marketplace transactions and subscriptions. When intent is already high, the role of the authentication system should be to verify the user without unnecessarily interrupting the decision that has already been made.

This means brands should evaluate login friction by where it appears in the customer journey, not simply by measuring the login page in isolation.

A five-second delay in account settings is not necessarily equivalent to a five-second delay at checkout.

Context determines the commercial cost.

Returning Customers Are Especially Valuable — and Especially Vulnerable

Login friction creates an unusual problem because it can punish some of the brand’s most valuable users.

A returning customer has already purchased, created an account or established a relationship with the company.

The business wants that person to return.

Yet returning users are exactly the people most likely to encounter forgotten passwords, outdated credentials or account-recovery flows.

This creates a contradiction.

The brand has already spent money acquiring the customer, but the authentication system can make the second purchase harder than the first.

That is particularly damaging because retention economics generally depend on reducing friction over time.

The customer relationship should become easier as the business learns who the user is.

If every return visit begins with another authentication problem, the opposite happens.

Password Requirements Can Become a UX Debt

Complex password policies often begin with good intentions.

Require an uppercase letter.

Add a number.

Include a symbol.

Use a minimum length.

Avoid previous passwords.

The difficulty is that complexity accumulates for the user.

Baymard’s research has repeatedly observed that extensive password requirements create frustration and can make later sign-ins harder because users construct credentials simply to satisfy the rules and then struggle to remember them on their next visit.

This creates a form of UX debt.

The security requirement may be implemented once, but the customer pays its usability cost on every future authentication attempt.

For brands still dependent on passwords, optimisation therefore matters even before adopting passwordless technology. Clear requirements, password visibility options, good autofill support and reliable recovery flows can reduce unnecessary friction significantly.

“Forgot Password?” Is Part of the Conversion Funnel

Password recovery is often treated as a technical utility page.

It should be treated as part of the customer journey.

If a customer reaches “Forgot password?” while trying to buy something, the reset flow has effectively become part of checkout.

That means its email delivery speed, messaging, mobile usability and ability to return the user to the original task all affect conversion.

A poor reset experience can break the journey completely. The user may receive the email on another device, lose the cart, encounter an expired link or create a new password only to discover that the site has forgotten what they were trying to purchase.

The brand should therefore ask a very simple question:

After account recovery, does the customer return exactly where they left off?

If not, the recovery process is creating marketing leakage.

Authentication Can Affect Brand Perception

Login problems do not remain isolated inside the authentication experience.

Users attribute them to the brand.

A customer rarely thinks:

The identity infrastructure has a suboptimal recovery implementation.

They think:

This website is annoying.

Or:

Why is buying something from this company so difficult?

That perception matters because convenience itself becomes part of brand positioning.

A company can spend heavily on premium visual design, performance marketing and customer service while still creating an experience that feels outdated because basic access is difficult.

Authentication therefore contributes to digital brand quality.

A smooth sign-in feels invisible.

A bad one becomes memorable.

Social Login Reduced Friction but Created Another Dependency

“Continue with Google”, “Sign in with Apple” and similar options became popular partly because they solved the password problem from the user’s perspective.

Instead of creating another credential, customers could authenticate using an identity they already maintained elsewhere.

That can dramatically simplify onboarding.

But social login also creates dependency on external identity providers and can raise questions around account linking, data sharing and what happens if the user loses access to the underlying provider.

This does not make social login a poor choice. It illustrates a broader principle: every authentication shortcut moves friction somewhere else.

The objective is not to remove every dependency.

It is to understand which dependencies create the best balance of security, convenience and customer control.

Passkeys Change the Marketing Value of the Login Screen

With traditional authentication, the login screen is mostly a defensive interface.

Enter the credentials.

Prove who you are.

Move forward.

Passkeys create the possibility of turning that interaction into something closer to a continuation of the customer journey.

A returning user can be recognised and asked to authenticate using a method that already feels familiar from unlocking their device.

That creates an opportunity for brands to stop treating authentication as a separate technical event and start treating it as part of experience design.

The ideal login may eventually be the one the customer barely notices.

That is particularly valuable for mobile experiences, where every extra field, keyboard interaction and context switch creates additional friction.

Mobile Makes Authentication Friction More Expensive

Login problems are amplified on smartphones.

Typing a long password is less convenient.

Switching between an app and email for a verification code interrupts the flow.

SMS messages may arrive late.

Password managers may not recognise a field correctly.

A user may be standing outside, travelling or completing the purchase with one hand.

This means the same authentication flow can feel acceptable on desktop and cumbersome on mobile.

For brands where a large share of traffic or purchases comes from smartphones, authentication should therefore be tested as a mobile conversion flow, not merely as a security component that happens to appear on a small screen.

Biometrics and passkeys are particularly relevant here because they build on gestures users already perform repeatedly throughout the day.

Too Many Authentication Options Can Create Friction Too

There is also a paradox in offering choice.

Password.

Passkey.

Email link.

SMS.

Google.

Apple.

Facebook.

Authenticator app.

More options may appear customer-friendly, but an overloaded login screen can create uncertainty about which identity the user used previously.

A returning customer may ask:

Did I create a password?

Did I use Google?

Was it Apple?

Is this passkey connected to the same account?

The result can be authentication choice overload.

Good UX therefore requires more than adding every possible sign-in method. The system should help returning users recognise the fastest path back into their existing account.

The objective is not maximum authentication choice.

It is minimum authentication confusion.

Account Creation Should Feel Smaller Than the Value It Unlocks

Every account request is an exchange.

The brand asks the customer to spend time creating and maintaining an identity.

In return, the account should provide visible value.

Faster checkout.

Saved addresses.

Order tracking.

Loyalty benefits.

Preferences.

Subscriptions.

Useful history.

If the account offers little more than the ability to receive promotional email, the authentication effort can feel disproportionate.

This is why marketers should evaluate account creation as a value proposition, not simply a CRM mechanism.

The customer is effectively asking:

Why should I create another account here?

If the answer is weak, even a technically perfect sign-up flow may struggle.

Authentication Metrics Should Sit Beside Conversion Metrics

Many businesses monitor:

conversion rate,

checkout abandonment,

customer acquisition cost,

repeat purchase,

and cart completion.

Far fewer marketing teams actively look at:

login success rate,

password-reset completion,

time to authenticate,

authentication abandonment,

or the percentage of customers forced into recovery.

Those metrics can reveal hidden conversion losses.

If a large share of users reaches the checkout but authentication success suddenly falls, increasing advertising spend will not fix the underlying problem.

The brand may simply send more customers into the same bottleneck.

Authentication analytics therefore belong closer to CRO and customer-experience reporting than many businesses currently treat them.

A Faster Login Is Not Valuable if Customers Do Not Trust It

Removing friction cannot come at the expense of confidence.

An authentication experience can become so unfamiliar that users hesitate because they do not understand what is happening.

A prompt asking to “Create a passkey”, for example, may feel simple to someone who understands the technology and suspicious to someone encountering the term for the first time.

This makes communication important.

The brand does not need to teach public-key cryptography, but it should explain enough for the user to understand:

what is being created,

where it will be stored,

how it will be used,

and what happens if they change devices.

The best authentication experience combines low effort with high confidence.

Speed without understanding can create a different kind of friction.

Login Friction Is Often Invisible in Marketing Attribution

A customer arrives through paid search.

Clicks the product.

Adds it to the cart.

Attempts to sign in.

Fails.

Leaves.

Depending on the analytics setup, the marketing team may simply see an abandoned checkout.

The root cause may never appear in campaign reporting.

This creates an attribution problem.

The acquisition channel did its job.

The landing page worked.

The product generated purchase intent.

But authentication broke the journey.

Without connecting identity and UX data to conversion analysis, marketers can easily optimise the wrong part of the funnel.

That is why login friction belongs inside a wider view of conversion leakage.

Passwords Also Create Costs Behind the Customer Experience

The visible marketing problem is abandonment.

Behind that sits another layer of cost: password-reset emails, support contacts, recovery systems, fraud controls and identity infrastructure.

The forthcoming Market Insiders article, “The Authentication Cost: What Businesses Pay for Password-Based Identity” will examine this operational side of authentication and why passwords can create costs long after the login screen has been designed.

For marketers, this matters because better authentication can generate two forms of value at once.

It can reduce customer friction while also reducing the operational work required to support that friction.

Understanding Passkeys Will Become Part of Digital Literacy

As passwordless authentication becomes more common, consumers will increasingly encounter passkeys across phones, browsers and computers.

That means the quality of adoption will depend partly on whether people understand the new interaction well enough to trust it.

The forthcoming Techrow.gr article, “Passkeys Explained: How Passwordless Login Works on Your Phone and Laptop” will take the practical technology angle: how passkeys are stored, what happens across devices and what users should expect when they replace or lose a phone.

For brands, the implication is important.

The transition should not be designed only for security teams.

It also needs product design, UX writing, customer support and marketing communication.

The Best Authentication May Be the One Customers Stop Noticing

A login screen does not generate demand.

It does not explain the product.

It does not create desire.

Its role is to allow an already interested user to continue.

That makes authentication unusual within the customer journey: success often means becoming almost invisible.

The customer should not leave the experience thinking about how impressive the login process was.

They should simply reach the thing they came to do.

That is why login friction deserves more attention from marketers. Every unnecessary field, failed credential, missing code or confusing recovery step introduces a chance for purchase intent to disappear.

Security still matters.

Identity still matters.

But authentication should protect the customer without forcing the customer to fight the brand.

When that balance is right, removing login friction does more than improve UX.

It protects the conversion that marketing worked to create.

Frequently Asked Questions

 

What is login friction?

Login friction refers to the additional effort or obstacles users encounter when trying to authenticate, including forgotten passwords, verification codes, account-creation requirements and complicated recovery processes.

 

Can login friction reduce conversions?

Yes. Authentication problems can cause users to abandon sign-in, account creation or checkout. Baymard’s usability research has documented checkout abandonment linked specifically to password and password-reset difficulties.

 

Why are passwords a conversion problem?

Passwords can be forgotten, mistyped or rejected because of complex requirements. Recovering them introduces additional steps at exactly the moment a customer may be trying to complete a high-intent action.

 

Are passkeys better for conversion?

They can reduce authentication time and improve login success in some implementations. FIDO’s Passkey Index and individual case studies such as Mercari report higher authentication success and faster sign-ins compared with other methods, although results vary by implementation and audience.

 

Should e-commerce sites require customers to create an account?

Not necessarily. Guest checkout can reduce unnecessary friction, while optional account creation can be offered after the purchase. Baymard recommends avoiding account-creation interruptions that distract users from completing checkout.

 

Does reducing login friction mean weakening security?

No. Technologies such as passkeys are designed to combine simpler authentication with stronger phishing resistance. The objective is to remove unnecessary user effort rather than remove security controls.

 

What authentication metrics should marketers monitor?

Useful metrics include authentication success rate, login abandonment, password-reset completion, time to authenticate and the percentage of customers entering account-recovery flows, alongside traditional conversion and checkout metrics.