Exactly. Same principle of passkeys, Yubikeys and FIDO2. Much harder to phish because the domains have to match.