Sigh, I got all excited, but then discovered this is to be used with a server, which means it fundamentally propagates the idea of "fake security" (where somebody else owns your identity, not you. Check out this explainer for more info: https://gun.js.org/explainers/data/security.html ).
This is bad design philosophy, I instead encourage everybody to use the native Web Crypto API to create accounts and do P2P E2EE encryption.
Web Auth API does look a lot easier than Web Crypto API, but it pushes the wrong message. We've taken a lot of time to make an MIT/Zlib/Apache2 Open Source wrapper around Web Crypto API that allows better user security (better than Web Auth API), short tutorial here: https://hackernoon.com/so-you-want-to-build-a-p2p-twitter-wi... .