OAuth consent is not proof of identity

Clicking "allow" gives an application access. It does not verify anything about that application.

The consent screen is genuine and comes from a service you trust, which is exactly why consent phishing works. The screen is telling you what permissions are being requested, not whether the requester deserves them. Reading what is actually being asked for, rather than whose logo is at the top, is the part people skip.

More on OAuth and federation