You claim to not have access to credit card information or being able to order something, but I already have to trust you to believe that claim. Also, Amazon could change their policies at any time -- after all you have credentials, Amazon could decide to trust you.
You will find that both are not possible
I can imagine it would be much, much easier for such social-engineering replacement fraud to happen if someone actually had access to your account with all of its order number data in the clear.
They would be restricted to just reordering things you've already ordered in the past, but I imagine that it doesn't take too many incidents on your account (especially if they figure out you've given your password away freely to a third party) before Amazon shuts you down, with all of the pain associated with that if you're a prime/kindle/etc user.
This seems like a cool service, but there's no way in hell I'm giving anyone my Amazon password for any purpose.
[0] http://www.htmlist.com/rants/two-for-one-amazon-coms-sociall...
I am not foolish enough to believe that my attackers are no more clever than myself. So whether I can extract my credit card from my account is not useful.
In order to trust you with credentials, it is necessary that you show you have thought everything through. The user needs to know that you will not leak credentials. It's a very high bar. You have simply failed to clear the bar.
To do that as well, it needs to be an extension and it should also monitor whenever you buy something. If there is a concern that purchases might happen when on another computer, you could allow the user to enter their password into the extension so that the extension can monitor things for you in the background. While users don't have a guarantee that the extension is using the password securely, at least it is possible for the source code to be inspected.
There is no way I'm giving out my Amazon creds which also house AWS, Amazon Payments, Amazon Sellercentral, etc...
Much more cumbersome for users but I see a report option where you can generate .csv's of every item you ordered, maybe those could be uploaded to your service, but unfortunately if I can't use this service without handing over my creds I'm not going to use it.
http://www.amazon.com/gp/help/customer/display.html?nodeId=2...
No. Asking people to give out their passwords is fucking horrific. You can't do anything with Amazon, but bad_guy could do something with $other_service and you're just encouraging people to be lazy with passwords.
It's hard enough to get people to choose good passwords and not store them in stupid ways.
Gaining this trust, though, will probably not be easy. One advantage a site like Mint has is that they have so much content and so many partnerships that it is clear they are not a scam, have enough at stake to not misuse my information, and probably have the resources to keep it safe. A site like yours, however, could easily have been cobbled together in a number of hours by a scammer. (I don't mean this as a criticism -- I actually like your site. It just doesn't have anything on it to suggest that you are the sort of business I can trust with my passwords.)