In addition to what Robby said, use an excludeCredentials list on create to prevent overwriting a passkey in the same provider.