Fido security stick instead of master password?

Thanks to all contributors for making valutwarden available.

I am running valutwarden 2024.1.2 in a docker on a Synology NAS. I have registered a SOLO2 Fido security stick and wanted to use it as authentificator instead of the master password.

When I log into vaultwarden web, it first asks for the master password and in the second step I can choose between various authentification methods including the security stick (which then works). I am wondering why I still need to enter the master password? Isn’t the security stick to replace passwords? If still some password should be entered, a weaker PIN could be enough in conjunction with the stick?

For unlocking the vault in the bitwarden extension (2024.4.1) of Firefox, the master password is required, while a security stick is not offered as an option. Is this correct or do I need to reconfigure something that I can use the security stick instead?

I am using a generated master password that I can’t or don’t want to remember and therefore I was looking into password free secure alternatives. That’s why I bought the stick.

The security stick is a second factor, not a single factor login device.

Also, Bitwarden needs the master password to decrypt the vault. We currently do not yet support passkeys to login into the vault for example.