Here's my proposal:
A single, standardized HTTP endpoint, "/.well-known/passwordchange/", where you can POST with query parameters "userid", "oldpassword" and "newpassword" and the server returns either a 200 on success or something else on non-success. That's it.