A few MB is acceptable for https POST these days. This gets hashed down to 64 chars or whatever.
EDIT: Down voters. What pw hashing algo are you using instead of BCrypt or similair?
That said, a few MB is a lot for one client to post if you have a significant amount of traffic. Just hash client side first.