How is that different from mutual TLS authentication?
Edit: It seems like OPAQUE just initiates mutual TLS authentication after the TLS session has already been negotiated with PKI. So it basically just allows websites to design their own login page instead of the one designed by the web browser.
Giving permission by saying yes to a “would you mind” question is the hill I die on. Usually I say “I would not mind” but if I’m feeling frisky I’ll say no and watch their brain melt.