Or even no switch at all. Like daisy chain the AP's with their internal multipleLAN ports. Which, ok, are actually switches.
Be definition, a switch that does not have an IP for itself, no GUI or console access, is a 'dumb' switch, like a smart hub. You can not interact with it. It will operate on MAC level at max, not IP.
Btw : I don't get it.
It took you a minute to create a (example) VLAN ID 100 on pfSense.
It takes a minute to set up a device (= AP, or whatever) with a static IP setup for this VLAN100 (which means the IP should be in the VLAN100 network, the gateway should point to the VLAN100 pfSense IP - same thing for its DNS).
Set up also the VLAN ID for your 'LAN' on the AP - if the AP supports VLAN.
Hook up the AP, and analyse the traffic with firewall rules that log, or the packet sniffer or whatever, to assure yourself that LAN and VLAN traffic is separated.
Or .... apply the keep-it-simple rule : take a 5 $ third NIC, create your physical separated wired LAN, hook up your switch and on the switch the 5 AP's and you can pas on to other things ;)