Edit: fixed the domain to actually make the point I was trying to make.
https://internal.yourcompany.com/oauth2/callback?token…
That token in the callback does not require any kind of cookie to use for subsequent authenticated calls.
In 2020 my friend couldn't add a new credit card to his account because browsers updated their same-site cookie behavior.
They were setting their JSESSIONID cookie wrong when doing oauth behind-the-scenes which caused a nice 302 redirect loop. For whatever reason the API calls required both *.battle.net and account.blizzard.com.
You have to activate them for the login but you can deactivate afterwards.
They finally fixed it this year. Made it impossible for me to login on my Firefox browser.
Sony Playstation website also broke until like three years ago with third-party cookies disabled.