[Qubes OS] Nitrokey 3 for KeePassXC

What is the ideal design and how can it be implemented for security keys to protect KeePassXC (Fedora38 or Debian11) on Qubes OS (R4.2+)?

I will link here (@ion Arch, @nku Debian/Ubuntu) from other OS discussions about KeePass.

Do you do the HMAC key setup as described here?