Google separates two cases. A multilingual site offers content in more than one language; a multi-regional site explicitly targets users in different countries. Many sites are both (Managing Multi-Regional and Multilingual Sites). For all of them, Google recommends a separate URL per version and hreflang annotations, which can be given in HTML, in HTTP headers or in a sitemap. Google calls the three methods equivalent and says using more than one has no benefit in Search (Localized Versions of your Pages).
The rules are specific. Each version must list itself and every other version, using fully-qualified URLs. Annotations must be reciprocal: If two pages don't both point to each other, the tags will be ignored. Codes are a language in ISO 639-1 format with an optional region in ISO 3166-1 Alpha 2 format, and a region alone is not valid. Reserved or wrong region codes, such as UK, have no effect. Where several URLs target one language in different locales, Google suggests a catch-all page for that language, and recommends x-default as the fallback for unmatched languages, designed for language selector pages. Google does not use hreflang or the HTML lang attribute to detect a page’s language.
We cover hreflang and market structure as part of technical SEO. On the technical SEO page, hreflang sits under the question of which version counts, alongside canonicals, duplicates and parameters.