In theory, this kind of problems was what OAuth was designed to solve - access to protect (private) resources by requesting the user's permission. In practice, I'm not sure if it's trusted enough in terms of security to be used for this. Giving access to CC or SS numbers is 'somewhat' more sensitive than letting someone post on your Twitter account.