They absolutely do not and also introduce a significant amount of overhead with respect to key/certificate management.
Which is totally fine to do over HTTPS.
It is far better to give service XYZ a time-bound and scope limited token to perform a request than a user's username and password.