I think even when integrating a social login, a developer still needs to create a secure cookie and has "user" table in his/her database. Using social login is rather a convenient option for users as they don't have to create a new account.
Sure, but the stored credential is not reusable in another context. Which is not true for the majority of passwords. As a bonus, the authorization is probably also revocable via the external identity provider, although that's more about service-to-service permissions than account compromise.