Skip to content

Which Auth Method? Explained

Answer a few questions about your client, your state, and your revocation needs to find the right authentication flow: session cookies, JWT, OAuth2, or API keys.

There is no single best auth method. The right one depends on who the client is, whether you can keep server-side state, and how fast you must revoke access. Answer below to get a recommendation, ranked against the alternatives.

Decision guide · 4 options

The options

Session (cookie)

Server keeps state, the browser carries an opaque cookie.

First-party web apps in a browser, where you can store sessions server-side and revoke them instantly.

JWT

A signed, self-contained token the client sends on each request.

Stateless APIs, microservices, and mobile or SPA clients where you want no session store and can tolerate delayed revocation.

OAuth2

A redirect dance through an identity provider that issues tokens.

Letting users sign in with a third party (Google, GitHub) or letting one service access another on the user's behalf.

API key

A long-lived secret sent in a header on every request.

Simple server-to-server or partner integrations where a shared secret is enough and per-user identity is not needed.

Which one fits you?

Answer a few questions to get a recommendation.

Question 1 of 3

Who is the client making requests?