Problem type
Second factor required
mfa-required
What it means
Removing a user's last second factor in self-service while the environment requires one. On the hosted pages and on the management API's /me, removing a passkey that is the user's last way to sign in is also answered with mfa-required, whatever the policy; the account API answers that case with last-credential.
What to do
Add another factor first. Taking a user's factors away altogether is an administrative reset, not a self-service removal.