Authentication is to prove who you are - authorization is to just have permission to do
something, as a subset of authenticated rights.
You would generally be much less rigorous in the Facebook example between giving someone access to your shared photo albums than to your account settings. Having an oauth token does not make you signed into Facebook at all, but just says that you have valid rights to do something.