Skip to main content

Run Custom Code

Applies to: Run Custom Code 1.0.0, 1.1.0
The Run Custom Code action runs JavaScript or Python inside your workflow. Use it for logic that formulas cannot express: parsing complex JSON, multi-step transformations, or a calculation that would need deeply nested branches.
Run Custom Code is available on paid plans.
You don’t need to write code from scratch. Click Help me write code in the code editor, describe what you want in plain language, and the AI assistant generates the code for you.

How the step works

  1. Data to use in the code: name the values your code needs and map them to outputs of earlier steps. The code reads them from inputData.
  2. Language and Code: write the body of a function. Whatever you return becomes the output of the step, available to later steps as body.
Run Custom Code action with JavaScript

Run Custom Code action with JavaScript extracting a domain from an email

Reading input data

Every entry of Data to use in the code is a key of inputData. A value that is exactly one variable keeps its type: a number stays a number, a record stays an object, a list stays an array.

Returning a result

Return any JSON-compatible value: an object, a list, a string, a number or a boolean. Later steps reference it through the variable menu as body, or a field of it. A thrown error or a raised exception fails the step, and the message appears in the run details and in Test your step.

Cryptography

Both languages come with a cryptography module. The code can hash values, compute and check HMAC signatures, and decrypt or verify data that a partner encrypted or signed with RSA.

JavaScript: crypto and Buffer

Version history
  • Added to 1.0.0 and 1.1.0 in September 2026.
crypto is the Node.js crypto module: createHash, createHmac, privateDecrypt, publicEncrypt, sign, verify, randomUUID and the rest of it. Buffer converts between text, base64, hex and raw bytes.

Python: rsa

Version history
  • Added to 1.0.0 and 1.1.0 in September 2026.
import rsa gives you the API of the rsa package: rsa.PrivateKey.load_pkcs1 and rsa.PublicKey.load_pkcs1 read a PEM or DER key in PKCS#1 or PKCS#8 form, rsa.decrypt and rsa.verify accept the ciphertext or signature as base64 text or as bytes, and rsa.encrypt, rsa.sign, rsa.DecryptionError and rsa.VerificationError work as in the package. Padding is PKCS#1 v1.5.
Keep private keys and secrets out of the code. Pass them in through Data to use in the code, mapped from a place only the right people can read, such as a record in a table with restricted access. The code then stays readable, and the same key is not repeated in every step that needs it.

Calling HTTP APIs

JavaScript can call HTTP APIs with the Node.js http and https modules. Return the promise of the result; the step waits for it.
Python code has no network access. In JavaScript, localhost and the cloud metadata addresses are blocked.

Runtimes and limits

When something fails

  • A script error fails the step with the message of the error or exception. Test the step to see it while you write the code.
  • Async script timed out, Execution timed out and Memory limit exceeded name the limit the run hit. Split the work between steps, or narrow the data the step receives.

Versions

Steps created with an earlier version of Run Custom Code keep working. The Applies to line at the top of this page names the versions the page covers. An Applies to line under a heading names the versions that section applies to; without one, a section applies to every version of the page. A Version history block under a heading lists what changed for that part.
Building workflows as code? The Softr Workflows CLI keeps every Run Custom Code step in a real .js or .py file next to the workflow definition.