List configured OAuth servers without stored tokens.
Servers are drawn from the same trust-gated resolution as run_mcp_login,
so untrusted project-level entries are excluded from the scan.
A server counts as needing login when it opted into OAuth and has no
stored token at all. Expiry is deliberately not consulted, matching the
runtime's upfront gate in resolve_and_load_mcp_tools.