I have yet to see any solid, significant evidence that passkeys are materially more secure than a random 32-character password + TOTP 2FA.
If a site or app refuses to let me create my own login and forces me to use a provider, I’m not going to be a customer under any circumstances.
If a site or app refuses to let me use a password+TOTP combination (as in, it forces passkeys), I am similarly out.
That’s not to say I don’t use passkeys. I have them on my Microsoft accounts, for one. But that is only after I have fully set up the account, and that the account plays very nice with the Microsoft Authenticator app, even going so far as to do challenge-response auth in coordination with the app, and plumping TOTP up to 8 characters.
Will I switch to passkeys elsewhere? Not for some time to come. My passwords make use of the entire two-byte UTF-8 character set, in that less than ½ of all characters typically generated can be found on a U.S. keyboard. So long as websites don’t restrict password length to moronically short values, a 32-character password with 2,048 possibilities for every character ought to be reasonably difficult to crack.
And then, of course, comes TOTP 2FA.