I've recently been looking into passkeys and it seems much simpler than this.
OIDC works for things like "use my employer's login to get access to AWS resources without having a separate AWS password".
For certain OIDC authentication implementations, you can actually use passkeys. Standard passkeys should work perfectly fine with Keycloak's WebAuthn implementation, for example, either as a second factor or as the first factor in the login flow.