A practical field guide from Automation Ace.
The short answer
Code by Zapier is great for small snippets, but custom code that grows (longer runtimes, npm packages, shared logic, secrets, tests, or high volume) is often better hosted in Cloudflare Workers. Your Zap calls the Worker with a Webhooks by Zapier request, and the Worker does the heavy lifting. The five main reasons: fewer runtime limits, real packages and tooling, reusable logic across Zaps, better secret handling, and lower cost at volume.
For background, see Cloudflare Workers 101 and code automation.
1. Escape tight runtime and memory limits
Code by Zapier steps have short time limits and modest memory that vary by plan, and long requests risk timeouts. Workers handle longer network waits, and heavy or long jobs can move to Workflows or Queues with retries.
2. Use npm packages, TypeScript, tests, and Git
Code steps offer a limited set of built-in libraries (see JavaScript libraries in Code steps and Python libraries). A Worker project can bundle npm packages, use TypeScript, run unit tests, and live in Git with code review and history. See version control for automations.
3. Reuse one piece of logic across many Zaps
When the same snippet is copied into ten Zaps, every fix means ten edits. A Worker endpoint centralizes the logic; every Zap calls the same URL, and one deploy updates them all. It works like a Sub-Zap or webhook relay, with real code.
4. Handle secrets and security properly
API keys pasted into Code step input fields are visible to anyone who can edit the Zap. Worker secrets are encrypted and never mapped through Zap fields. You can also verify signatures, add auth to your endpoint, and restrict what the code can reach. See API authentication and the security checklist.
5. Lower cost at high volume
Code steps count as tasks. Moving compute-heavy or high-frequency logic to Workers (with a generous free tier and low-cost paid plan) can reduce task usage while the Zap still orchestrates. Better yet, a Worker can receive events directly and only call Zapier when a no-code step adds value. See reducing task usage and free-plan automations.
How to migrate a Code step to a Worker
Before (Code by Zapier):
// Code by Zapier (JavaScript) — inputData in, output out
const res = await fetch(`https://api.example.com/customers/${inputData.id}`, {
headers: { Authorization: `Bearer ${inputData.api_key}` },
});
const customer = await res.json();
output = { tier: customer.tier, ltv: customer.lifetime_value };
After (Worker):
// Cloudflare Worker — called from a Zap with Webhooks by Zapier (POST)
export default {
async fetch(request, env) {
if (request.headers.get('X-Token') !== env.ZAP_TOKEN) return new Response('Unauthorized', { status: 401 });
const inputData = await request.json(); // same fields the Code step used
const res = await fetch(`https://api.example.com/customers/${inputData.id}`, {
headers: { Authorization: `Bearer ${env.CUSTOMER_API_KEY}` }, // secret, not a mapped field
});
if (!res.ok) return Response.json({ error: `Upstream ${res.status}` }, { status: 502 });
const customer = await res.json();
return Response.json({ tier: customer.tier, ltv: customer.lifetime_value });
},
};
- Copy the logic into a Worker.
inputDatabecomes the parsed JSON body;outputbecomes the JSON response. - Move keys to secrets with
npx wrangler secret put. - Protect the endpoint with a shared token header.
- Replace the Code step with Webhooks by Zapier → POST (or Custom Request) to the Worker URL, sending the same fields as JSON. See Webhooks by Zapier.
- Map the response fields into later steps exactly as before.
- Test side by side with a few real records, then switch over. See testing a Zap.
Already on AWS? The same pattern works with a Lambda Function URL; see AWS Lambda for beginners.
When to keep Code by Zapier
- Short snippets such as formatting, simple math, and small transforms. See string transforms in Code steps.
- Logic used by one Zap that rarely changes.
- Teams without anyone to own a Worker deployment.
- Cases where an extra network hop would add risk or latency for no benefit.
Not sure where your code belongs? See Zapier consultant vs in-house developer or talk to Automation Ace.
Frequently asked questions
Why move Code by Zapier logic to Cloudflare Workers?
To escape runtime and memory limits, use npm packages, TypeScript, tests, and Git, reuse one piece of logic across many Zaps, store secrets securely, and reduce task usage at high volume.
How do I call a Cloudflare Worker from a Zap?
Use a Webhooks by Zapier POST or Custom Request action with the Worker URL, send the fields your code needs as JSON, include a secret token header, and map the JSON response into later steps.
Is it safe to put API keys in Code by Zapier input fields?
Anyone who can edit the Zap can see mapped input values. Storing keys as encrypted Cloudflare Worker secrets keeps them out of Zap fields.
When should I keep code in Code by Zapier?
For short, simple snippets used by one Zap, when no one can own a Worker deployment, or when an extra network call adds no benefit.
Will moving code to Workers reduce Zapier tasks?
Replacing a Code step with a webhook step keeps a step in the Zap, so savings come from consolidating logic, or from letting Workers handle events directly and only calling Zapier when needed.
Disclaimer: Zapier features, plan availability, and settings can change. Confirm current details in Zapier's help documentation and Cloudflare's developer documentation and pricing pages. Limits and plan features change over time. Code samples are simplified starting points; add your own validation, error handling, and security review before production use before relying on a specific setting. This article may include links to apps, products, or services; some links may be affiliate links, which means Automation Ace may earn a commission at no extra cost to you.