An AES key is symmetric. Both parties need it for this cryptographic operation.
The OTP key is separate from other keys that enable WebAuthn.
Also, please don't use Yubikey OTPs. While they can't be brute forced like TOTPs, they can be phished. There are better technologies to implement.