i think this depends upon the websites implementation of fido2/passkey for requiring the user to authenticate. If you get a prompt for pin it means “user verification” is required as apart for authenticating.
You can test this feature on https://webauthn.io/ and try making the “user verification” as preferred or discouraged. If the user verification is discouraged it will simply authenticate you without pin and just the touch.