Of course the website itself would need to support that, but it's all possible in time.
I suppose client cert would protect against from a MitM attack, if the client failed to notice it, or if the MitMer has the website keys to make a perfect attack.
https://privacysandbox.google.com/blog/update-on-plans-for-p...