Run Custom Code
Applies to: Run Custom Code 1.0.0, 1.1.0The Run Custom Code action runs JavaScript or Python inside your workflow. Use it for logic that formulas cannot express: parsing complex JSON, multi-step transformations, or a calculation that would need deeply nested branches.
Run Custom Code is available on paid plans.
How the step works
- Data to use in the code: name the values your code needs and map them to outputs of earlier steps. The code reads them from
inputData. - Language and Code: write the body of a function. Whatever you
returnbecomes the output of the step, available to later steps asbody.

Run Custom Code action with JavaScript extracting a domain from an email
Reading input data
Every entry of Data to use in the code is a key ofinputData. A value that is exactly one variable keeps its type: a number stays a number, a record stays an object, a list stays an array.
Returning a result
Return any JSON-compatible value: an object, a list, a string, a number or a boolean. Later steps reference it through the variable menu asbody, or a field of it. A thrown error or a raised exception fails the step, and the message appears in the run details and in Test your step.
Cryptography
Both languages come with a cryptography module. The code can hash values, compute and check HMAC signatures, and decrypt or verify data that a partner encrypted or signed with RSA.JavaScript: crypto and Buffer
Version history
- Added to 1.0.0 and 1.1.0 in September 2026.
crypto is the Node.js crypto module: createHash, createHmac, privateDecrypt, publicEncrypt, sign, verify, randomUUID and the rest of it. Buffer converts between text, base64, hex and raw bytes.
Python: rsa
Version history
- Added to 1.0.0 and 1.1.0 in September 2026.
import rsa gives you the API of the rsa package: rsa.PrivateKey.load_pkcs1 and rsa.PublicKey.load_pkcs1 read a PEM or DER key in PKCS#1 or PKCS#8 form, rsa.decrypt and rsa.verify accept the ciphertext or signature as base64 text or as bytes, and rsa.encrypt, rsa.sign, rsa.DecryptionError and rsa.VerificationError work as in the package. Padding is PKCS#1 v1.5.
Calling HTTP APIs
JavaScript can call HTTP APIs with the Node.jshttp and https modules. Return the promise of the result; the step waits for it.
localhost and the cloud metadata addresses are blocked.
Runtimes and limits
When something fails
- A script error fails the step with the message of the error or exception. Test the step to see it while you write the code.
- Async script timed out, Execution timed out and Memory limit exceeded name the limit the run hit. Split the work between steps, or narrow the data the step receives.