Currently, all applications have at least the "basic rights" grant, allowing reading and basic use of the api.
To provide a better user experience for apps that only want to authenticate, and not make authorized calls, OAuth should allow a way to create apps that have no rights.
Additionally, apps that primarily intend to authenticate with the wiki have no way to get access to the authenticating user's email or real name, so having an "authenticate only, and have access to private information" would be nice.