"Passkeys" appears to be another name for FIDO Multi-Device.
FIDO previously took the position that the private keys should never leave your hardware token (or phone). Because that's the most secure position.
That position appears to be out the window. They provide a rather longish obscure FAQ entry explaining, yeah, we said your private key shouldn't leave your token (or phone), but times are a' changing.
From the FIDO multi-device FAQ: https://fidoalliance.org/faqs/#multi-device-fido-credentials
From the FIDO Alliance website: "FIDO Alliance has previously stated that user authentication credentials never leave the device. Has that changed?"
"FIDO Alliance’s mission is to help reduce the world’s over-reliance on passwords. It is true that some relying parties (and their users) get value out of hardware-bound credentials, and the FIDO standards still support this type of deployment.
But for many relying parties, the fact that FIDO’s approach required users to enroll each new device presents some customer usability challenges, and also limits their ability to replace passwords (as passwords frequently serve as a means to verify new authenticator enrollment).
As such, replacing the password with a challenge-response protocol based on asymmetric cryptography is a huge step forward in security, even if those cryptographic keys aren’t bound to hardware – as this helps RPs thwart the constant threats of phishing, credential stuffing and other remote attacks."