greetd
greetd is a minimal login manager that hands the login screen to a separate greeter such as tuigreet, ReGreet or noctalia-greeter. Gaze authenticates there through the shared PAM stack, the same way it does on LightDM.
Setup
greetd's PAM service includes the shared authentication stack, so enabling Gaze the usual way is enough:
sudo pam-auth-update --packagesudo authselect select gaze with-silent-lastlog --forcesudo pam-config --add --gaze
sudo pam-config --updateSome distributions also ship a greetd-greeter service. That stack runs the greeter program itself, not your login, and Gaze never releases a keyring credential to it.
Confirm with gaze doctor, then log out and authenticate with your face.
GNOME Keyring unlock
A face login supplies no password, so pam_gnome_keyring.so has nothing to unlock the keyring with and prompts once the desktop is up. Gaze can hand it a TPM-protected copy of your password instead, as it does for GDM.
Turn on template encryption, liveness and GNOME Keyring unlock in gaze config, then enroll the password:
sudo gaze config
sudo systemctl restart gazed
gaze keyringRe-enroll after a TPM clear or a change to the account or keyring password.
The PAM edit
/etc/pam.d/greetd already has a keyring line, but it does not take the token:
auth optional pam_gnome_keyring.soAdd use_authtok and leave the line where it is:
auth optional pam_gnome_keyring.so use_authtokKeep the existing session optional pam_gnome_keyring.so auto_start line. Gaze does not edit this file for you because it belongs to the distribution.
Unlike gdm-face, greetd uses one stack for both face and password logins, so there is no pam_deny gate. The keyring line only has to come after system-auth. A face match hands it the stored password, a typed password hands it what you typed, and with neither it does nothing.
For greetd, use the PAM configuration shown here rather than copying the pam_gaze.so line from gdm-face or hyprlock. The [success=1 ...] control would skip the keyring line, while sufficient or [success=done ...] would end the auth section before it runs.
sudo gaze doctor checks the order, not just the option.
What this changes about your security
Everything in the GDM security notes applies. In addition, greetd's stack is the full session stack rather than a face-only one, so after a face match the password is visible to the modules that follow the keyring line. On Fedora that is postlogin and, on a KDE install, the pam_kwallet5.so and pam_kwallet.so lines.
SELinux
On Fedora the greeter needs the gaze-greeter-keyring policy module to read the stored record. gaze keyring loads it, and sudo gaze doctor reports it as Keyring SELinux policy. Without it the login still succeeds and the keyring prompts as before.
Troubleshooting
gkr-pam: no password is available for user in journalctl -b means the keyring line is missing use_authtok, sits before system-auth, or is skipped by a pam_gaze.so line above it. sudo gaze doctor reports all three under Keyring.