Authorization Code Flow Implementation: Access Token vs Cookie-Based Authentication from Browser

facing a similar situation. any preferred method you found?