I mean, they're basically just client SSL certs, but used for auth instead of transport

It's entirely possible for server side app to tie a client certificate to a user account and offer one click login and it has been since the 90s.