@johanneskastl

Yes, just wanted to drop what I think is the case with #kwallet. Any process can request any data (correct me if I am wrong @kde)

For encrypted user data at rest, #systemdHomed could work, but I have not seen easy implementations of that.

#KeepassXC can also act as secret service. But A even #KeepassXCBrowser is kinda janky, and I like to have separate stores depending on the importance.

(I am one of the people who use Firefoxes pw manager 🫣)

Other things I'm thinking about is using #SystemdHomed (which better GNOME support is being worked on! <3) and TPM2/FIDO unlock (with a password) of the homed (instead of passwd-password) + also unlocking the keychain.
Decided to live dangerously and use all the new shinies too, so I'm running #btrfs on root, with #systemdHomed for my user account, Gnome on #Wayland, and #Pipewire as my audio server. So far I've run into surprisingly few bugs or mis-configurations (even my RX580 and 3 monitors work fine). Perhaps the best news is that Orca is now quite stable under Wayland. Only thing it's missing is mouse-click emulation, which sucks, but I can mostly deal with. And everything feels buttery smooth.