Automation Blog

JavaScript and Node.js Libraries Supported in Zapier Code Steps: What's Available and How to Use Them

A reference guide to the Node.js built-in modules, global APIs, and pre-installed npm packages available inside Zapier's JavaScript Code steps — what you can use, what constraints apply, and how to work effectively within the environment.

ZapierJavaScriptCode Steps

By Troy Tessalone · · 4 minutes

Automation Guide

A practical field guide from Automation Ace.

JavaScript and Node.js Libraries Supported in Zapier Code Steps: What's Available and How to Use Them

Zapier's Code by Zapier action includes a JavaScript option — a sandboxed Node.js runtime that executes inside a Zap step, receives data from previous steps as the inputData object, and returns values to subsequent steps via a output object. The JavaScript environment comes pre-configured with Node.js built-in modules, a set of pre-installed npm packages, and a global fetch API for HTTP requests. Knowing what is available before you write a Code step saves time and prevents the frustration of a missing module at runtime. This article covers the JavaScript and Node.js libraries available in Zapier Code steps and the practical implications of the environment constraints.

The Zapier JavaScript Runtime Environment

Zapier's JavaScript Code steps run in a server-side Node.js sandbox. You cannot install packages with npm, cannot write to a local filesystem, and cannot import arbitrary npm packages — you work with what is provided. The JavaScript version is Node.js (Zapier documents the specific version in their help documentation — check Zapier's current Code step documentation for the exact version, as it is updated over time).

Input data from previous Zap steps is available in the inputData object. The Code step must call output = {...} or callback(null, {...}) to return values — the keys and values of that object become the output fields available to subsequent Zap steps. Unlike Python Code steps, which use a return statement, JavaScript Code steps use the output variable assignment pattern.

The fetch Global: HTTP Requests Without a Library

The most important thing to know about Zapier's JavaScript Code step environment is that a global fetch function is available — you do not need to require anything to make HTTP requests. This is the primary way to call external APIs from a JavaScript Code step:

const response = await fetch('https://api.example.com/data', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'Authorization': 'Bearer ' + inputData.apiKey
  },
  body: JSON.stringify({ key: inputData.value })
});
const data = await response.json();
output = { result: data.someField };

The fetch global in Zapier Code steps supports async/await — the Code step environment handles asynchronous execution. This covers the vast majority of API call patterns needed in automation workflows.

Node.js Built-In Modules

Core Node.js built-in modules are available via require(). Commonly used modules that work reliably in Zapier Code steps include:

  • crypto — cryptographic hashing (MD5, SHA-256), HMAC signatures for API authentication, random bytes generation
  • querystring — URL query string parsing and serialization (note: URLSearchParams is also available as a global)
  • url — URL parsing and construction
  • path — path string manipulation utilities
  • util — utility functions including util.promisify for converting callback-style functions
  • buffer — binary data handling, base64 encoding and decoding via Buffer.from(str, 'base64')
  • stream — stream utilities (limited practical use in the Code step sandbox)
  • events — EventEmitter (limited practical use in the sandbox)
  • assert — assertion utilities for validation checks

The JSON global object (parse, stringify) is available without any require — it is a standard JavaScript built-in, not a Node.js module.

Pre-Installed npm Packages

Zapier's JavaScript Code step environment includes a curated set of pre-installed npm packages available via require(). The most commonly used include:

  • lodash — utility library for array manipulation, object transformation, string operations, and more; const _ = require('lodash')
  • moment — date parsing, formatting, and manipulation; const moment = require('moment') — note that moment is in maintenance mode; for timezone handling use moment-timezone
  • moment-timezone — moment extended with IANA timezone support; const moment = require('moment-timezone')
  • bluebird — promise library with utilities like Promise.map for concurrent async operations
  • xml2js — XML parsing and building; useful when working with SOAP APIs or XML webhook payloads
  • cheerio — server-side HTML parsing with jQuery-like syntax, the Node.js equivalent of BeautifulSoup
  • marked — Markdown to HTML conversion
  • z — Zapier's own utility object, available as a global in Code steps; provides z.console.log() for logging visible in Zap run history

Zapier maintains a help article listing the currently available packages — always verify against Zapier's current documentation, as the available packages change as the runtime is updated. The Zapier community thread at community.zapier.com is a useful community-maintained reference for what is currently available.

Zapier's z Object

In JavaScript Code steps, Zapier exposes a global z object with utilities specific to the Zap execution context:

  • z.console.log() — logs output visible in the Zap run history; essential for debugging Code step behavior
  • z.JSON.stringifyForLogging() — serializes objects for safe logging

The z object is the same utility available in Zapier's CLI-built integrations (via the Zapier CLI and platform SDK), adapted for the Code step context. Using z.console.log() instead of console.log() is the recommended pattern because the output is visible in Zapier's Zap run history, making debugging significantly easier.

What Is Not Available

The JavaScript Code step sandbox intentionally excludes capabilities that would conflict with its server-side, multi-tenant execution model:

  • No file system access — fs module is not available; data must flow through inputData and out through output
  • No subprocess execution — child_process is not available
  • No arbitrary npm package installation — the package set is fixed at runtime
  • No browser APIs — window, document, DOM manipulation, and browser-specific globals are not available (this is a Node.js environment)
  • No native add-ons or binary dependencies
  • No access to environment variables beyond what Zapier provides through the execution context

If you need a library that is not available in the Code step environment, the alternatives are: use a standard built-in equivalent, restructure the Zap to pre-process the data in an earlier step, or move the logic to an external service (an AWS Lambda function, a Cloudflare Worker, or a Make scenario) that the Zap calls via a Webhooks step. For a comparison of when to use Code steps versus API by Zapier or Webhooks by Zapier, see the dedicated guide.

The global fetch function combined with crypto, lodash, and moment-timezone covers the vast majority of what JavaScript Code steps are used for in Zapier: calling APIs, computing HMAC signatures, transforming data structures, and handling dates across timezones. If you are reaching beyond that set, evaluate whether a Code step is the right tool or whether the logic belongs in an external service.

Practical Patterns for JavaScript Code Steps

The most common uses of JavaScript in Zapier Code steps:

  • Computing an HMAC-SHA256 signature for a webhook verification header using crypto.createHmac('sha256', secret).update(payload).digest('hex')
  • Parsing and transforming a complex JSON payload from a webhook that Zapier's native field mapping cannot handle cleanly
  • Making a multi-step API call — authenticate with one request, use the token from the response in a second request — using fetch with async/await
  • Date arithmetic and timezone conversion using moment-timezone for formatting dates to specific API requirements
  • Flattening, grouping, or restructuring arrays of data using lodash utilities like _.groupBy(), _.keyBy(), or _.pick()
  • Parsing XML webhook payloads using xml2js when working with legacy systems or SOAP APIs

For the Python equivalent of this guide, see Python libraries supported in Zapier Code steps. For a broader look at when to use Python and JavaScript in automation workflows, see the dedicated guide. For help writing a JavaScript Code step for a specific use case, talk to Automation Ace.

ZapierJavaScriptCode Steps

Disclaimer: This article may include links to apps, products, or services. Some links may be affiliate links, which means Automation Ace may earn a commission at no extra cost to you.

Build Better Systems

Ready to automate with confidence?

Share your tools, process, and goals. Automation Ace can design the workflow, integration, AI assist, or code bridge that fits your business.

Start a Project →