Passphrase encryption with multiple FIDO2 hardware keys — fully client-side
Any listed key can later decrypt the file independently.
Create a resident (discoverable) credential on your FIDO2 hardware key. Only needed once per physical device. Requires a PRF-capable key (e.g. YubiKey 5) and Chrome 116+.