The options
Session (cookie)
Server keeps state, the browser carries an opaque cookie.
First-party web apps in a browser, where you can store sessions server-side and revoke them instantly.
JWT
A signed, self-contained token the client sends on each request.
Stateless APIs, microservices, and mobile or SPA clients where you want no session store and can tolerate delayed revocation.
OAuth2
A redirect dance through an identity provider that issues tokens.
Letting users sign in with a third party (Google, GitHub) or letting one service access another on the user's behalf.
API key
A long-lived secret sent in a header on every request.
Simple server-to-server or partner integrations where a shared secret is enough and per-user identity is not needed.
Which one fits you?
Answer a few questions to get a recommendation.
Question 1 of 3