How do you store sensitive data in mongodb

It depends heavily on the third party service.
Usually services that give you API access will supply you with a token or cookie that will allow you to make repeated calls to a service. When you need a users credentials to get this token, you often have to have the user visit the other site either manually or though a pop up in order to get the token.
This is essentially what happens with the third party login services like google or facebook login.
If you provide more details on what the credentials actually are, I can provide more advice.

P.S. on the off chance you are asking how to store a users password to a service you don’t directly control, the short answer is you shouldn’t
There is no way to do this securely, however if you absolutely must do so, ensure that the password for the service is encrypted before being stored in the database and the key stored on some other secure system. This won’t protect you against online attacks, but if you database is compromised and downloaded, then it offers some protection.