I loathe these kinds of security measures that make up literally impossible tasks for some people.
There should always be a break-glass. That break-glass should not be tied to a piece of hardware. That's why I don't use 2FA unless there are break-glass OTP, or I can use a generic authenticator. Authy, for example, allows me to install 2FA on my phones and desktop - no need to worry about losing my phone meaning I can't get into my accounts.
My bank on the other hand, uses Symantec VIP, which has no backup or break-glass. So my bank (the only one offering 2FA) is 1FA.
Most OTP systems will show you a bunch of recovery codes you can write down or print out or email yourself or whatever you want to do with them.
Authy is a great option but annoyingly it's tied to your phone number rather than a username, so you can lose access to that if you break your phone in a place where you can't easily get a new SIM card (i.e. if you're on holiday). You also need to remember to actually enable multi device in the settings, as it's off by default. It's a good service, but it's not without its own pitfalls.
I'm always wary of custom 2FA systems that banks and governments like to use, especially if they do nothing to actually avoid phishing. If you're going to make your own version of TOTP, at least solve the biggest problems TOTP faces. For this reason I like to configure krypt.co as my primary 2FA method (for as long as that's kept running) with TOTP (and optionally device-local webauthn) as a backup solution.
There should always be a break-glass. That break-glass should not be tied to a piece of hardware. That's why I don't use 2FA unless there are break-glass OTP, or I can use a generic authenticator. Authy, for example, allows me to install 2FA on my phones and desktop - no need to worry about losing my phone meaning I can't get into my accounts.
My bank on the other hand, uses Symantec VIP, which has no backup or break-glass. So my bank (the only one offering 2FA) is 1FA.