One thing that is crucial is that websites MUST support multiple Passkeys per account, otherwise you end up with a single point of failure if something happens to your password manager.
It's good that you can't export a Passkey, which reduce the attack vector against phishing and extraction. It's kinda like how an SSH or a GPG private key should never leave the computer it was generated from, and each machine should have their own unique private key.