Also, forgot to mention:
If you were to use WebCrypto, it ought to be possible to securely (with respect to cross-origin policy) store a user's private key using IndexedDB.
If you were to use WebCrypto, it ought to be possible to securely (with respect to cross-origin policy) store a user's private key using IndexedDB.
WebCrypto has support for keypairs that can have the private key data extracted (there are limits, though, which I cannot accurately remember) from the JavaScript object in which they are contained.
So it ought to be possible to extract the key data, encrypt it (also using WebCrypto) and sync it (somehow) to another device.
Add key for <user@website> at <utcmillisecs>: <new_public_key_goes_here>;<sign>
Again, having a command ("Add key ..." as in parent message) for this would make this feature accessible to password/key managers.