Token-based authentication was covered, in passing, here:
https://paragonie.com/blog/2015/04/secure-authentication-php...
Our strategy (designed for a "remember me" checkbox) is actually a little more cautious than a simple nonce, in that we actually generate two tokens:
One is a selector (used to retrieve a record from the database, which is an operation that cannot be performed in constant time), while the other is a validator.
We store an SHA256 hash of the validator in the database. When the auto-login is invoked, we pull the hash and destination user ID from the database (based on the selector), the compare
if (hash_equals(hash('sha256', $verifier), $storedHash)) {
$_SESSION['userid'] = $storedUserId;
$this->generateAndStorePersistentToken(storedUserId);
}
The blog post details it a bit further.