it's SE limitation :(. also makes me sad, will be awesome if you can import a key generated by yourself. so if you reinstall you can import again to the enclave
[0]: https://www.yubico.com/support/security-advisories/ysa-2017-...
Basically treat this the same as you would a physical 2fa token.
Without an export it could maybe be one key in a multisig.
I tried to look up the info, but the only thing I found was this: "But because its backing storage is physically part of the Secure Enclave, you can never inspect the key’s data."
https://developer.apple.com/documentation/security/certifica...
That means that it get stored in SE instead of your computer's hard drive. Also, Apple have instructions to clean Secure Enclave if you're going to sell your macbook pro with touchid.