I am less willing to use something like this for passwordless logins. These types of devices should be part of the "something you have" part of 2FA, which should always be paired with a "something you know".
Maybe I'm missing a step here, but why would you ever use this for passwordless?