The classic web approach: on login the server creates a session, stores state, and sets a cookie with the session id. The browser sends the cookie automatically on each request. Mark it HttpOnly (JS can't read it — blocks XSS theft), Secure (HTTPS only), and SameSite (CSRF defense). Stateful but easy to revoke (delete the session).