Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
Passkeys (WebAuthn/FIDO2) with synced credential managers became the default strong-auth choice: phishing-resistant, no shared secrets. Password + TOTP is the legacy tier; plan account recovery carefully.
OAuth 2.1 (still draft, 16th revision) consolidates best practice: no implicit flow, PKCE required, exact redirect matching. DPoP (RFC 9449) sender-constrains tokens — the practical answer to token exfiltration.