So, the correct way to approach this in WebAuthn, which you'll see in popular implementations of its predecessor U2F and in for-real WebAuthn deployments is that users are allowed to have any plausible number of tokens, in GitHub this feels especially natural because it's managed the same way as your SSH keys, you can add or remove them, give them labels that help you remember what they are, and then you use any of them to prove your identity.
So I have a cheap FIDO token on my keychain that I take everywhere, and then I have one permanently plugged into the big desktop PC in my home and one in a desk drawer. You can buy ones that work nicely with a phone (unless you have an iPhone, can't help Apple) and Microsoft intends to effectively build one into Windows installs.
If you see a WebAuthn deployment that does 1:1 users to FIDO tokens, those people don't know what they're doing and need re-educating just like when people go "Oh, MD5(password) seems pretty secure".