Would love to see FIDO2 / Webauthn in SSH. Working with PKI tokens for key auth works but has to be set up in the client.

You should take a look at https://github.com/gravitational/teleport

Disclaimer: I'm one of the contributors.