microG can do large parts of FIDO2 (as in U2F hardware key), passkeys were (better) specified in CTAP 2.1. For those discoverable credentials support seems around the corner, but the question of what stores + distributes the pkeys remains for the user / OS to provide (in the microg PR they’re put into screenlockcredentials.db, feels prototypish). I’d expect 1-2 more months of fleshing this out.
Independently you can use any implementation (and storage/distrib mechanism). Here’s a thread showing the use of bitwarden, generating pkeys off-device. You could use this today: Update about passkeys on /e/OS 2.6