HTTP basic auth, TLS with client certs.
Which is totally fine to do over HTTPS.
It is far better to give service XYZ a time-bound and scope limited token to perform a request than a user's username and password.
[0]: https://groups.google.com/a/chromium.org/g/blink-dev/c/z_qEp...