Help me please to understand correct flow to SSO with a mobile app for backend services
Now I'm using the next scheme:

My unauthorized mobile appwants to auth in my service through SSO (facebook and google). It has clientId, clientSecret and required scopes forMy service.My mobile appauth with vendor SDK, for example, on Facebook.My mobile appgive back authorization token.My mobile appsends authorization token in the auth request toMy service.My serviceuses this token to get information about a user from a remote identity provider. For example, get a user identifier or email withFacebook Graph API. This identity used to authenticate and authorize a user (my own RDB).My servicereturn JWT token toMy mobile app(if auth success). This token is used for the next request toMy serviceAPI.
Is it correct to send Oauth2 token from the app to backend?
Can you point out the ​errors of the current approach?