Just spitballing here, but it seems like a good mix of phishing resistance & lockout recovery would be to have passkey-only auth, but with email recovery.
So no password login, but then you can recover your account by adding an additional passkey by receiving an email.