I am not sure I understand the point of using TPM + PIN to decrypt the drive for a single user system.
I am fine just using the passphrase and I just configure my graphical login manager to log straight to my preferred user on start in order to not have to type crefentials twice at boot time.
I found TPM + PIN to be more secure than TPM automatic unsealing, and faster than typing my long passphrase.
I haven't tried pam_autologin yet, but I see the convenience of it.
I am fine just using the passphrase and I just configure my graphical login manager to log straight to my preferred user on start in order to not have to type crefentials twice at boot time.