Possibly dumb question: why not use an Authentik outpost with a reverse proxy to enforce SSO? It wouldn’t be “baked in” so to speak, but it would be fully OIDC and as long as you’re just running it through a web browser. Biggest downside is you’d need 2 logins (one for the outpost and one for the app). I’d assume the sso is specifically for the extra security though, so that shouldn’t be a problem outside of it being a little hassle.
In my experience, Seagate exos are only “loud/clicky” when under HEAVY write loads. Mostly they’re pretty quiet with a very low drone at worst. In any decent case it’ll be pretty negligible. With headphones on doubly so.