Documentation index: llms.txt. This page is also available as markdown: append .md to this URL or send Accept: text/markdown.
Authentication Upgrade
Coalesce Transform is moving to a modern identity platform. This page covers what's changing, whether you need to do anything, and how to get help if you get stuck signing in.
This upgrade hasn't rolled out yet, so there's nothing to do today. Keep signing in as you do now. Coalesce lets you know before the change takes effect, so you don't need to watch this page for the switch.
What's Changing
The upgrade replaces the identity system behind Transform sign-in. Two things come out of it.
Stronger account security. Transform moves onto dedicated identity infrastructure, which gives your account better protection and gives Coalesce a foundation for improved security controls going forward.
One set of credentials across Coalesce. Catalog and Quality already run on this platform. Bringing Transform across means the same credentials work for all three products, so there's one password to manage instead of a separate one for each. You may still be prompted to sign in when you open another Coalesce product, but you'll use the same credentials every time.
The rollout happens in the coming weeks. Coalesce lets you know before the upgrade takes effect for your organization, and an announcement appears in Transform.
When the upgrade takes effect for your organization, your current session ends and you're signed out of Transform. Signing back in is how you'll notice the change, so it's worth setting your new password once the upgrade reaches you rather than waiting to be interrupted mid-task. Work you've already saved isn't affected.
Who Needs to Take Action
What you need to do depends on how you sign in today. Find your sign-in method in this table.
| How you sign in | What you need to do |
|---|---|
| Email and password | Reset your password once the upgrade is live, using Reset password on the sign-in page |
| Single sign-on (Okta, Microsoft Entra ID, Google Workspace, SAML) | Nothing right now. Your organization's single sign-on moves separately at a later date, and Coalesce coordinates that change directly with your IT team |
| Transform API Tokens | Nothing. Tokens aren't affected and don't need rotating |
Why a Password Reset Is Needed
Passwords are never stored in a readable form. They're stored as one-way cryptographic hashes, which is exactly what makes them secure. The previous system and the new one use different hashing methods, and by design a hash can't be converted from one to the other. Existing passwords can't carry across, so everyone who signs in with an email and password sets a new one.
A password reset done before the upgrade goes live applies to the old system and won't carry over. Wait for the notification that the upgrade is live.
How to Reset Your Password
Once the upgrade is live, resetting your password takes about a minute. This is a one-time step.
The reset uses an email challenge to confirm it's you. Coalesce sends a link to the address on your Coalesce account, and selecting that link is what verifies the request came from you. You can't complete the reset without access to that inbox, so make sure you can receive mail there before you start.
- Go to your Coalesce Transform sign-in page.
- Enter the email address on your Coalesce account and select Continue.
- On the password screen, select Reset password.
- Confirm your email address and select Continue. A Check Your Email screen confirms the request.
- Open the email from
support@coalesce.ioand select the reset link. - Choose a new password and sign in.
Reset links expire. If yours has expired, repeat these steps to get a new one.
Before the Upgrade Reaches You
Because the reset is verified by an email challenge, both of these are worth doing ahead of time.
Allowlist the reset email sender. The most common problem people hit is that the reset email never arrives, because their organization's mail filtering blocks or quarantines it. If you're an IT administrator, allowlist support@coalesce.io ahead of the rollout.
Confirm your email address is current. Check that the address on your Coalesce account is one you can still access. If you can't open mail at that address, you won't be able to complete the reset.
What Stays the Same
The only thing changing is how you sign in. Everything you build and everything that runs on a schedule is untouched.
- Transform API Tokens aren't affected. Scheduled Jobs, CI pipelines, and integrations keep running, and no rotation is needed.
- Your Projects, Nodes, and Workspaces are unchanged.
- Your role and access stay the same.
If anything about your access looks wrong after you sign in, contact Coalesce Support.
Password reset links only ever come from support@coalesce.io, and they only ever point to a Coalesce domain. If an email claiming to be a Coalesce password reset looks off, don't select the link. Forward it to Coalesce Support instead.
Troubleshooting
Most sign-in questions after the upgrade fall into one of the following situations.
Transform Signed You Out Without Warning
This is expected on the day the upgrade reaches your organization. Existing sessions end so that everyone signs in through the new identity platform. Sign in again, resetting your password first if you use an email and password.
The Sign-In Page Looks Different
This is expected. The new sign-in page is served by the upgraded identity provider, so it's the same URL with a new design. Sign-in is also split across two screens now: you enter your email address first, select Continue, and enter your password on the next screen.
A Prompt Asks Which Organization to Sign In To
This is also expected if you belong to more than one Coalesce organization. Choose the organization you're working in.
The Reset Email Didn't Arrive
Check your spam folder and your mail quarantine, and confirm you entered the exact email address on your Coalesce account. Select Resend email on the Check Your Email screen to send it again. If your organization filters external mail, ask your IT team whether support@coalesce.io is allowed. If nothing arrives after 15 minutes, contact Coalesce Support.
Because the reset is verified by email, there's no way to finish it without receiving that message. If the address on your account is one you can no longer open, contact Coalesce Support rather than requesting more links.
The Reset Link Expired
Request a new link by selecting Reset password again on the sign-in page.
Scheduled Jobs and API Integrations
Automation keeps running. Transform API Tokens aren't part of this upgrade and don't need to be rotated.
What Changes for Single Sign-On Administrators
Your organization's single sign-on isn't part of this rollout, so nothing changes for your users yet. They keep signing in as they do today.
Separately, single sign-on is moving to a model where you configure one connection that covers Transform, Catalog, and Quality together, rather than setting up each product on its own. Moving to that model is required to use the shared credentials across all three, and existing single sign-on configurations are retired after a transition period. This is a coordinated, scheduled change, and Coalesce reaches out to plan it with you, including anything you need to update on your side such as allowlisted sign-in URLs.