Although, I think MCP is not really appropriate for this either. (And frankly I don't think chatbots make for good UX, but management sure likes them.)
The story for MCP just makes no sense, especially in an enterprise.
MCP is basically just an RPC API that uses HTTP and JSON, with some other features useful for AI agents today.
If you use the official MCP SDK, it has interfaces you implement for auth, so all you need to do is kick off the OAuth flow with a URL it figures out and hands you, storing the resulting tokens and producing them when requested. It also handles using refresh tokens, so there's just a bit of light friendly owl finishing on top.
Source: I just implemented this for our (F100) internal provider and model agnostic chat app. People can't seem to see past the coding agents they're running on their own machines when MCP comes up.
This might help if interested - https://vectree.io/c/implementation-details-of-stdio-and-sse...
You absolutely DO want to run everything related to LLMs in a sandbox, that's basic hygiene