This is very likely insecure. A malicious web site could replay your Auth flow to another website where you have an account that uses the same keypair.
does this have a name? always seemed like the obvious way to do it but I've never implemented auth
edit: I guess this is similar to a challenge/sign/verify signature scheme like webauthen, but is it inferior in some way?
The advantage is that your private key can't be leaked on a third party website.
I feel like I knew that already. ;)