I have a primary 'vault' qube that holds all the credentials for all qubes, and then use Firefox's built-in password management on a per-qube basis. There is an initial 'config' step where I'll need to pass credentials from the Vault qube to an App qube, but after that it's smooth+automated.
Alternatively, you could use a vault-per-qube model.