There is currently no OAuth, which sounds like what you're asking for.
Currently you need to trust the app and your instance. Most instances are implementing off-the-shelf lemmy but there is no way to confirm that.
Lemmy apps could steal your password if they wanted to, but if you use an open source app through say F-droid that compiles the apps from source, you can check the code if you have that skillset.
Ultimately the answer here though is not to trust your instance or app, but to instead not need to. Your account should be treated as disposable and (like every other site) you should be using a unique password not used anywhere else.
This way it doesn't matter if your instance steals your password, since they already know everything you've given them. Lemmy is all public anyway so there isn't much risk involved.
I'd argue the biggest risk is if your instance requires email validation, and it's easy enough to use a relay email (Firefox Relay, Simplelogin, Addy.io, etc) so that's unique as well.