Perhaps you'd be interested in reading about Secure Remote Password (SRP): https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...
Copying the "layman's terms" from that page for your convenience...
In layman's terms, during SRP (or any other PAKE protocol) authentication, one party (the "client" or "user") demonstrates to another party (the "server") that they know the password, without sending the password itself nor any other information from which the password can be derived. The password never leaves the client and is unknown to the server.