So trying to create an account and set the password via an input (content format set to password) that then gets sent to a API workflow where the account is created and a password is manually assigned from that input.
Sure - I agree, not exposing the password makes sense in the logs and database. But the workflows described above should work I would have thought.
I’ve used another workaround via the API workflows just using the standard ‘Sign up the user’ so at least a custom password can be specified or otherwise if not just use the password reset method for new users: