but what do passkeys offer in terms of security, when stored in password managers, compared to having a (password manager) generated password and a totp?

I believe that by allowing password managers to store passkeys, the whole purpose of "device based security" got lost..

They are 100% immune to credentials phishing. You literally cannot authenticate to an impersonator site based on cryptographic guarantees.

And yes, I know the happy path of password managers uses host-based autofill which does add some friction to phishing attempts, but given the prevalence of unexpected but legitimate urls with weird alternate subdomains/SSO/redirects in modern login flows, you have to manually autofill/add an exception often enough that it's possible to let your guard down once at the wrong time.

Yes. I use hardware based passkeys and absolutely love them. I think it was a giant mistake having them 'software' based. It some ways it kind of defeats the entire purpose...