====test==== Making a request (and not including any credentials) to an endpoint, which security depends on global security definitions, results in a 401 status code response. ====spec==== swagger: '2.0' paths: /todos: get: responses: 200: description: OK schema: type: number securityDefinitions: BasicAuth: type: basic ApiKeyAuth: type: apiKey in: header name: X-API-Key security: - BasicAuth: [] - ApiKeyAuth: [] ====server==== mock -p 4010 ${document} ====command==== curl -i http://localhost:4010/todos ====expect==== HTTP/1.1 401 Unauthorized www-authenticate: Basic realm="*" {"type":"https://stoplight.io/prism/errors#UNAUTHORIZED","title":"Invalid security scheme used","status":401,"detail":"Your request does not fullfil the security requirements and no HTTP unauthorized response was found in the spec, so Prism is generating this error for you.","headers":{"WWW-Authenticate":"Basic realm=\"*\""}}