What would be the absolute best solution to use keepass and usbkey-app in Qubes?

What would be the absolute best way to use let’s say Keepass and usbkey-app in Qubes? Keepass have been installed in vault already by default. Would some usbkey-2fa-app be best in sys-usb then and copy/paste to vault?
Just asking for the best solution in Qubes. I’m looking for a secure way to store my passwords. Thank you!