I’m quite sure that server set cookies are the norm for authentication, at least where they are set from the server side.