Does PAKE protect against scenarios like "password written on sticky note", "fake login page hosted at login.nnicrosoft.com", or "scammer impersonating IT staff"?
It does handle the second and third, IIRC.
Passkeys work because the user can't be tricked into entering their private key on a phishing website.