I use hybrid basic and cookie auth in my application.
Basic auth functions as a captcha and invite code, eliminating users not invited and almost all bots.
After that,s done, the user gets a cookie (and a private key in LocalStorage) and is not prompted next time.
The beauty of cookies and basic is that the cookie is sent before auth takes place.