> example.com provides a /.well-known/change-password resource which redirects to their change password form, wherever it happens to already be.
> Password managers check for the existence of /.well-known/change-password on https://example.com.
> If it's there (the response code is 2xx or 3xx), the password manager can cause the user's browser to navigate there when the user indicates they'd like to change their password.
It's not trying to enforce a particular password schema, it's not an API endpoint to automate changing passwords, and it is not trying to dictate site design or form layout.
It's also dirt simple to implement with practically zero cost.
Aside from Safari, it doesn't seem like any password managers have implemented this yet. It's also not in the IANA well-known URI registry [2] yet (even as draft), so that would probably at least allow it to get a bit more traction. Apparently they are working towards that [3].
[1] https://github.com/WICG/change-password-url/blob/gh-pages/ex...
[2] https://www.iana.org/assignments/well-known-uris/well-known-...
[3] https://twitter.com/rmondello/status/1042008520105779206