A practical field guide from Automation Ace.
JavaScript and Node.js Libraries Supported in Zapier Code Steps: What's Available and How to Use Them
Zapier's Code by Zapier action includes a JavaScript option — a sandboxed Node.js runtime that executes inside a Zap step, receives data from previous steps as the inputData object, and returns values to subsequent steps via a output object. The JavaScript environment comes pre-configured with Node.js built-in modules, a set of pre-installed npm packages, and a global fetch API for HTTP requests. Knowing what is available before you write a Code step saves time and prevents the frustration of a missing module at runtime. This article covers the JavaScript and Node.js libraries available in Zapier Code steps and the practical implications of the environment constraints.
The Zapier JavaScript Runtime Environment
Zapier's JavaScript Code steps run in a server-side Node.js sandbox. You cannot install packages with npm, cannot write to a local filesystem, and cannot import arbitrary npm packages — you work with what is provided. The JavaScript version is Node.js (Zapier documents the specific version in their help documentation — check Zapier's current Code step documentation for the exact version, as it is updated over time).
Input data from previous Zap steps is available in the inputData object. The Code step must call output = {...} or callback(null, {...}) to return values — the keys and values of that object become the output fields available to subsequent Zap steps. Unlike Python Code steps, which use a return statement, JavaScript Code steps use the output variable assignment pattern.
The fetch Global: HTTP Requests Without a Library
The most important thing to know about Zapier's JavaScript Code step environment is that a global fetch function is available — you do not need to require anything to make HTTP requests. This is the primary way to call external APIs from a JavaScript Code step:
const response = await fetch('https://api.example.com/data', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Authorization': 'Bearer ' + inputData.apiKey
},
body: JSON.stringify({ key: inputData.value })
});
const data = await response.json();
output = { result: data.someField };
The fetch global in Zapier Code steps supports async/await — the Code step environment handles asynchronous execution. This covers the vast majority of API call patterns needed in automation workflows.
Node.js Built-In Modules
Core Node.js built-in modules are available via require(). Commonly used modules that work reliably in Zapier Code steps include:
crypto— cryptographic hashing (MD5, SHA-256), HMAC signatures for API authentication, random bytes generationquerystring— URL query string parsing and serialization (note:URLSearchParamsis also available as a global)url— URL parsing and constructionpath— path string manipulation utilitiesutil— utility functions includingutil.promisifyfor converting callback-style functionsbuffer— binary data handling, base64 encoding and decoding viaBuffer.from(str, 'base64')stream— stream utilities (limited practical use in the Code step sandbox)events— EventEmitter (limited practical use in the sandbox)assert— assertion utilities for validation checks
The JSON global object (parse, stringify) is available without any require — it is a standard JavaScript built-in, not a Node.js module.
Pre-Installed npm Packages
Zapier's JavaScript Code step environment includes a curated set of pre-installed npm packages available via require(). The most commonly used include:
lodash— utility library for array manipulation, object transformation, string operations, and more;const _ = require('lodash')moment— date parsing, formatting, and manipulation;const moment = require('moment')— note thatmomentis in maintenance mode; for timezone handling usemoment-timezonemoment-timezone— moment extended with IANA timezone support;const moment = require('moment-timezone')bluebird— promise library with utilities likePromise.mapfor concurrent async operationsxml2js— XML parsing and building; useful when working with SOAP APIs or XML webhook payloadscheerio— server-side HTML parsing with jQuery-like syntax, the Node.js equivalent of BeautifulSoupmarked— Markdown to HTML conversionz— Zapier's own utility object, available as a global in Code steps; providesz.console.log()for logging visible in Zap run history
Zapier maintains a help article listing the currently available packages — always verify against Zapier's current documentation, as the available packages change as the runtime is updated. The Zapier community thread at community.zapier.com is a useful community-maintained reference for what is currently available.
Zapier's z Object
In JavaScript Code steps, Zapier exposes a global z object with utilities specific to the Zap execution context:
z.console.log()— logs output visible in the Zap run history; essential for debugging Code step behaviorz.JSON.stringifyForLogging()— serializes objects for safe logging
The z object is the same utility available in Zapier's CLI-built integrations (via the Zapier CLI and platform SDK), adapted for the Code step context. Using z.console.log() instead of console.log() is the recommended pattern because the output is visible in Zapier's Zap run history, making debugging significantly easier.
What Is Not Available
The JavaScript Code step sandbox intentionally excludes capabilities that would conflict with its server-side, multi-tenant execution model:
- No file system access —
fsmodule is not available; data must flow throughinputDataand out throughoutput - No subprocess execution —
child_processis not available - No arbitrary npm package installation — the package set is fixed at runtime
- No browser APIs —
window,document, DOM manipulation, and browser-specific globals are not available (this is a Node.js environment) - No native add-ons or binary dependencies
- No access to environment variables beyond what Zapier provides through the execution context
If you need a library that is not available in the Code step environment, the alternatives are: use a standard built-in equivalent, restructure the Zap to pre-process the data in an earlier step, or move the logic to an external service (an AWS Lambda function, a Cloudflare Worker, or a Make scenario) that the Zap calls via a Webhooks step. For a comparison of when to use Code steps versus API by Zapier or Webhooks by Zapier, see the dedicated guide.
The globalfetchfunction combined withcrypto,lodash, andmoment-timezonecovers the vast majority of what JavaScript Code steps are used for in Zapier: calling APIs, computing HMAC signatures, transforming data structures, and handling dates across timezones. If you are reaching beyond that set, evaluate whether a Code step is the right tool or whether the logic belongs in an external service.
Practical Patterns for JavaScript Code Steps
The most common uses of JavaScript in Zapier Code steps:
- Computing an HMAC-SHA256 signature for a webhook verification header using
crypto.createHmac('sha256', secret).update(payload).digest('hex') - Parsing and transforming a complex JSON payload from a webhook that Zapier's native field mapping cannot handle cleanly
- Making a multi-step API call — authenticate with one request, use the token from the response in a second request — using
fetchwithasync/await - Date arithmetic and timezone conversion using
moment-timezonefor formatting dates to specific API requirements - Flattening, grouping, or restructuring arrays of data using
lodashutilities like_.groupBy(),_.keyBy(), or_.pick() - Parsing XML webhook payloads using
xml2jswhen working with legacy systems or SOAP APIs
For the Python equivalent of this guide, see Python libraries supported in Zapier Code steps. For a broader look at when to use Python and JavaScript in automation workflows, see the dedicated guide. For help writing a JavaScript Code step for a specific use case, talk to Automation Ace.
Disclaimer: This article may include links to apps, products, or services. Some links may be affiliate links, which means Automation Ace may earn a commission at no extra cost to you.