I really do like that the pin is entered directly into the device for onlykey. This allows it to be used to safely unlock a computer, which is a feature Signet lacks.
The Trezor Model T has pin entry on the device too too (but that does not store passwords, it only does FIDO2 for authentication). This works fine for my machine, where I have FIDO2 logins set up, but most apps, websites and software don't support FIDO2.
Another issue that worries me is if the people making the device stop doing so. This happens all the time with corporate products being sunset. It also happened with the Signet! The original authors are gone. However, because it is fully open source, I was able to pick it up and start building devices. I plan on continuing support for at least as long as the components are still being manufactured.
In fact, it looks like OnlyKeys are currently sold out, which is exactly how my recent experience with Signet started. First it was sold out, then I didn't get a response to my inquiry as to when they'd be back in stock...
As long as everything is perfectly implemented in the firmware, the OnlyKeys really shine with the extra features like TOTP, FIDO2, and PGP support.
Personally, I know too much about software security for more features to be a selling point for me. I'm less confident in it's ability to withstand software only attacks when it is unlocked. Since I feel like one of the main points of using a hardware password manager over a software one is that it can remain relatively safe on a compromised computer, I feel like this is a pretty legit concern. This comes back to people's threat model though. If they assume there are not any dedicated attackers after either them or OnlyKeys, then this doesn't really matter in practice.
Signet is not immune from this either, but fewer features means less code to have exploitable bugs. And modern exploits will chain together a bunch of seemingly benign bugs to compromise a system, so the number of bugs is almost as important as their severity.
Anyway, thanks for letting me know about OnlyKeys. They didn't turn up when I was searching for alternatives. They're not a good fit for me, but based on the documentation, they seem like a pretty good solution for many people.