====test==== Supplying a header for Basic Authentication (when Bearer was needed) results in denied access. ====spec==== { "info": { "name": "Test" }, "auth": { "type": "oauth2", "oauth2": [ { "key": "addTokenTo", "value": "header", "type": "string" } ], }, "item": [ { "id": "3b4f5a70-2a8f-46ba-a04b-a6f80621ad3f", "request": { "url": { "path": ["todos"] }, "method": "GET" }, "response": [ { "code": 200, "description": "OK", "header": [ { "key": "Content-Type", "value": "application/json" } ], "body": "\"test\"" } ] } ] } ====server==== mock -p 4010 ${document} ====command==== curl -i http://localhost:4010/todos -H "Authorization: Basic dGVzdDp0ZXN0" ====expect==== HTTP/1.1 401 Unauthorized {"type":"https://stoplight.io/prism/errors#UNAUTHORIZED","title":"Invalid security scheme used","status":401,"detail":"Your request does not fullfil the security requirements and no HTTP unauthorized response was found in the spec, so Prism is generating this error for you.","headers":{"WWW-Authenticate":"Bearer"}}