In more detail
You approve the request at the service you already use, which then gives the app a limited, revocable access token (often a JWT) with specific permissions, called scopes. OAuth is about authorisation; the OpenID Connect layer on top adds proof of who you are. Apps should request only the scopes they need.