Just FYI, password rotation is currently considered an anti-pattern. I think we can imagine some kind of future where there's a common password protocol that user-facing services could talk that would allow certain entities with blessed access to rotate passwords without the user ever having to know about it, but in the current world, rotating passwords causes most users to use weaker passwords.