Skip to main content
Version: 1.28 (Current)

Code

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens

The Code actions run your own code when the built-in actions don't cover what you need. Depending on the action, the code runs in the user's browser or on the server, and it's written in JavaScript, C# (Razor) or PowerShell. The group also has Notes, which documents an action list without running anything.

Before writing code, check whether an existing action already does the job. Actions are easier to read, maintain and secure than custom code.

Choosing an action​

ActionLanguageRuns onResultUse it to
Execute Javascript Code And Continue ExecutionJavaScriptUser's browserNone. The remaining actions keep running on the server.Change the page, show a notice or send an analytics event, then carry on.
Execute Javascript Code And Stop ExecutionJavaScriptUser's browserNone. No later actions run.Finish with a browser-side step, such as opening a window or moving focus to a field.
Execute Javascript (Server)JavaScriptServerThe returned value, or each property of a returned object, in an output token.Calculate values or reshape JSON using tokens as variables.
Execute RazorC# (Razor)ServerThe text or HTML the script writes, in a token.Build HTML or text with C#, or use .NET and DNN APIs.
Run PowerShell ScriptPowerShellServerThe script's output, in a token.Run a short PowerShell script typed into the action.
Run ExecutableAny programServerEverything the program printed, in a token.Start a program or command line tool from an Automation job.
Execute Token (Obsolete)TokensServerThe result, in a token.Nothing new. Use Create/Update Tokens instead.
Notes--None. It does nothing at runtime.Leave development notes in an action list for other low-code engineers.

Browser or server?​

  • Browser (the two Execute Javascript Code actions). The code runs in the user's browser after the server sends it back, so it can change the page but can't read the database or other server resources. Errors only appear in the browser console. These actions are available in Forms and Listings.
  • Server (all the others). The code runs on the web server, as the identity of the application pool. It can reach anything that identity can, including files, the database and other systems. It runs before any response is sent to the browser.

Licensing​

All the Code actions except Notes and Execute Token (Obsolete) require the Scripting feature to be licensed. If it isn't, the action fails with a not-licensed error.

Tokens in code​

Actions handle tokens differently, so check each action's page:

  • Execute Javascript Code and Run PowerShell Script replace tokens inside the code before it runs. Values aren't escaped, so a token that holds user input can break the code or inject new code. Quote tokens, and avoid putting user input straight into code.
  • Execute Javascript (Server) and Execute Razor don't replace tokens in the code. Instead, every token is available as a variable in the script.
  • Run Executable replaces tokens in its arguments.

Considerations​

  • Security. Server-side code can do anything the application pool identity can. Only give edit access for these actions to people you trust, and never build code or command lines from untrusted input.
  • Maintenance. Code inside actions is harder to review than regular actions. Use the action's Description and a Notes action to explain what the code does and why. See Common Parameters.
  • Errors. Each action handles errors differently. Some fail the action, some only fill an error token, and browser code only logs to the console. Check each action's page before relying on it.

Revised 09/26/2026