Multi-factor authentication (MFA)

You can configure pamu2f Example (OnlyKey working config)

Universal 2nd Factor - ArchWiki

auth required pam_u2f.so cue [prompt=Please touch your FIDO2 device now] nodetect