Hum... HTTP has an entire authentication header.
There is also an entire set of standard practices to authenticate by cookies.
The only thing there isn't a standard is for handling authentication data with random code. As that's a pretty stupid thing to do.