So Yubikey would work. It identifies itself as a Keyboard to the OS.
These are HID devices, because they need to do challenge/response with the website that's trying to authenticate. The old OTP YubiKeys were keyboards. Better than nothing but phishable.