Why have a password at all? Just use webauthn if a device is available and skip the password completely (or give the user/dev a choice -- password sharing may make sense in a lot of contexts).
So long as we're able to get a strong static secret value from users, password or otherwise, that's all that matters. When we first looked into alternative auth mechanisms, it appeared that they did not provide us a value like that, but will definitely be looking further into webauth to explore this possibility some more, thanks for the tip