Use Windows Hello-Style Face Recognition for Passkeys on Linux with gaze-fido
After switching to Linux, I wanted to use my laptop’s face recognition to approve Passkey sign-ins in browsers, much like Windows Hello does.
My laptop has an infrared camera but no fingerprint reader. On Windows, Windows Hello used the IR camera for face recognition. On Linux, I can use Gaze for local face verification, but I still needed a way for the browser to use it as a FIDO2 authenticator.
I looked into how Windows Hello and Passkeys work, then started vibe-coding a solution: gaze-fido.
How it works
In short, gaze-fido registers a virtual FIDO2 authenticator through Linux’s UHID interface. The browser talks to it over CTAP2 to complete a WebAuthn or Passkey sign-in. The private key is protected by TPM 2.0, and Gaze performs local face verification when the authenticator is used.
The project is written in Rust and Qt. Websites see a standard FIDO2 authenticator, while I can approve a sign-in with the laptop’s built-in IR camera instead of plugging in a security key.
How it works for me so far
In my own use, Passkey sign-in works with Google and other sites. The project is still experimental and currently solves my own setup; I have not tried to turn it into a universal solution for every laptop, camera, or Linux distribution.
Maybe I’m the only one who needs it
The use case is admittedly niche: you need Linux, a compatible IR camera and TPM, and a reason to connect local face verification to a browser authenticator. Most people can use a phone, password manager, or physical security key instead.
Still, it was fun to build something I wanted and could actually use. If you have the same setup, this repository might help.