Pipedream

pipedream.comcontributed by Samuele Ongaro

ALMOST

A weekend of work, and real gaps remain.

Workflows written as code with hosted execution: each step is a Node or Python function, with managed authentication to hundreds of APIs and no server to run.

Promptfree, for everyone, and the only version there is
Build me code-based workflows that replace Pipedream — and know exactly what the fee buys.

It is **managed OAuth to hundreds of APIs**: token storage, refresh, revocation and the awkward per-provider differences. That is the genuinely tedious part, and it is unavoidable for each service you use — but for the three or four you actually use, it is an afternoon each rather than a platform. The rest, hosted execution with no server, you replace with one small machine that has no cold starts at all.

STACK
- Node 20+ with Fastify
- SQLite through better-sqlite3, WAL mode
- A worker process for the queue
- Steps are ordinary modules in your repository, deployed by your deploy
- Caddy in front

THE DATA MODEL
- workflows: id, key, version, definition_json, is_active — the definition is an ordered list of step module names and their configuration
- runs: id, workflow_key, workflow_version, trigger_payload_json, status, started_at, finished_at, error, dedupe_key
- step_runs: id, run_id, step_key, attempt, status, input_json, output_json, error, ms — the step cache, so a retry resumes rather than repeats
- connections: id, service, account_label, credentials_encrypted, scopes_json, expires_at, refreshed_at, last_error, revoked_at
- cursors, queue with leases, and an append-only event log

MANAGED OAUTH, THE PART THAT IS THE FEE
- One module per service implementing the same interface: build an authorisation URL, exchange a code, refresh a token, revoke, and describe the scopes
- Tokens encrypted at rest with a key from the environment, decrypted only in the worker
- **Refresh under a lock.** Two workers refreshing the same token at once will invalidate each other, and the resulting failure is intermittent and horrible to debug. One row, one lock, one refresh
- Refresh proactively before expiry rather than on a 401, and handle the provider that rotates the refresh token on every use — that one catches everybody once
- A connection that fails to refresh is marked and alerts, rather than silently failing every run
- Record the scopes granted, so a step needing more asks for reauthorisation instead of failing at the worst moment
- Write the two or three you need. A framework for services you have not integrated is wasted work

STEPS AS CODE
- A step is an exported function taking the run state and its configuration, returning a value. Plain code, in your repository, reviewed and tested like anything else
- Steps compose by name in the workflow definition, so the shape is data and the behaviour is code
- A sandbox for anything user-supplied: a time limit, no filesystem, no ambient network
- Secrets injected at run time, never in the definition

RELIABILITY
- The queue is a table with a lease; a crashed worker's run is reclaimed
- Retries with exponential backoff and jitter, per step, with a maximum
- Retry only what is safe: a step declares whether it is idempotent, and a non-idempotent one carries an idempotency key through to the service
- Deduplication on the trigger, so a redelivered webhook runs once
- A dead-letter list with a one-button replay

TRIGGERS
- Webhook with a secret and signature check, answering immediately and queueing
- Schedule with a cron expression and a time zone, both daylight-saving transitions tested
- Polling with a stored cursor and deduplication by item identifier — a poller that re-emits everything after a restart is the classic disaster
- Manual, with a payload typed by hand

THE INTERFACE
- Runs filterable by status with failures first, and a run view showing every step's input and output expandable
- A connections page showing each account, its scopes, when it was last refreshed and whether it is healthy. That page is what you will actually open

OPERATIONS
- .env: DATABASE_PATH, BASE_URL, ENCRYPTION_KEY, SESSION_SECRET, WEBHOOK_SECRET, per-service client ids and secrets
- Migrations on boot, each once; payload retention with a sweeper
- Nightly backup off the machine, restore script
- Health endpoint reporting queue depth, expired leases and any connection near expiry

WHAT MATTERS MOST
The refresh lock and the step cache. Those two are where a homemade version breaks — intermittently, at the worst moment — and they are both a day's careful work.

What you lose

  • Managed OAuth — token storage, refresh and revocation for hundreds of APIs, which is the genuinely tedious part
  • Hosted execution with no server, scaling and cold starts to think about
  • A registry of ready-made components you can read and fork

If you would rather not build

  • Cron plus a script, for two workflows

What it costs

as published on their pricing page

PlanBilled monthlyBilled yearlyLast read
—$29/mo——

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Windmill

$0

Runs scripts as workflows with schedules, secrets and a run history.

windmill-labs/windmillfree · open source

n8n

$0

Handles OAuth credentials for hundreds of integrations already.

n8n-io/n8nfree · open source

Why this verdict

our own opinion · changed only by a person

62/100

Verdict kinda at 62. Running the code is easy; storing and refreshing OAuth tokens for a dozen providers is the weekend, and doing it securely is the part to take seriously.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 1/day
views0130 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about Pipedream

answered from the record above

Is Pipedream free?

No — the plan we track is $29 a month. Basic from around $29/month billed monthly, priced on credits rather than on runs.

Can you replace Pipedream by building your own?

ALMOST. A weekend of work, and real gaps remain. Replacement score 62 out of 100, build time a weekend. Read what you lose before you decide.

How much does Pipedream cost?

$29 a month on Basic — $348 a year. Recorded 9 Aug 2026.

What do you lose by replacing Pipedream?

Managed OAuth — token storage, refresh and revocation for hundreds of APIs, which is the genuinely tedious part; Hosted execution with no server, scaling and cold starts to think about; A registry of ready-made components you can read and fork. If any of those carry weight for you, keep paying.

Is there an open-source alternative to Pipedream?

Yes: Windmill, n8n. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 17 in Automation & notifications

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc