I believe security keys are the offline version of passkeys you're looking for.
I am afraid that websites will somehow disable support security keys and only support passkey implementations from big tech (similar to how websites only offer signin with google, fb , etc).
Can someone clarify if WebAuthn protocol allows for this filtering against hardware authenticators?