You don't. The browser handles the passkey matching to the domain which is obviously a better place to do it. There could obviously still be bugs as with all things, but it's much more intentionally integrated into the flow which makes it much harder to bypass.
> The browser handles the passkey matching to the domain which is obviously a better place to do it.
I'm not sure why you're making a distinction. In many cases the browser is the password manager.