The browser can verify who am I, likely in a more rigorous way than a password.
The browser can already handle interaction with the server on behalf of the user.
Sure, the user flow would need to be sorted out (e.g., to confirm the user's intent), but it seems much better than the current system we've been using since the days of .htaccess.