For people confused about what this is: it's basically the de facto cross-browser standard for U2F security keys like Yubikeys.
In short, this could replace passwords for web authentication entirely.
And does it allow extensions, e.g. secure login through a smartwatch + NFC, and similar ideas?
There is also pam-u2f: https://developers.yubico.com/pam-u2f/
and https://github.com/bluecmd/openssh-u2f (not in upstream)
Oh, I guess client certs are owned and controlled by the server owner...
And with a better UI and flow since you don't need it to establish connection.
However the WebAuthn API also leaves options for password managers and other endpoints managing the actual secrets.