This is not a bug report but is a feature request to potentially allow instances to configure whether WebAuthn is a two-factor authentication method or not. Fluxer has made the decision, like Discord, that WebAuthn is a two-factor authentication method, and it is implemented as such. If it weren't required to login to your account, but you could just use an email and password, it is not two-factor authentication and it provides zero extra security. It only provides convenience. That may be a valid way someone wants their instance to work, however, and it is worth discussing as a feature request.
I believe you should have been offered the option to download backup codes when setting up WebAuthn as an MFA method. When you cannot access a specific MFA method, it is intentional that you cannot login to your account, since you do not have access to the MFA method in question. Otherwise it is not MFA. But with backup codes, you should be able to sign in to your account anyway. Let me know if this is not working as you expect, however, but this would be the solution to your problem at this time, aside from not using device-bound passkeys. Passkeys generally are a very poor UX and I wouldn't recommend them to most people. I'm open to practical suggestions, however.
Thread
Comment by Hampus
Comment by Hampus