I've recently implemented authentication for my project and I would just like to say to all the relatively amateur programmers out there: for web based authentication just stick with HTTPOnly SECURE cookies with DB backed sessions that you can revoke.
The reason I'm saying this is that there's way too many posts talking about JWT (which isn't suitable for newbies), Oauth (which is more useful if you have separate authentication and resource servers) and other token based mechanisms which are what cookies are except more suitable for non web based clients.