If a passwordless option was available too, i.e. email a TOTP code that is a nonce, and presentation of the TOTP would generate a JWT with the email address as the claim... then this would become my new login manager.
I'm presently using auth0 free plan. Which is nice, but passwordless lock (their JS library) is old, and their docs are not great as to how to update to their other lock library (I've concluded you can't stay passwordless with the main auth0 lock library).