leave-pipedream · checked

What Pipedream's workflow export leaves out

Pipedream's export page, read 9 October 2026, says the archive describes each workflow's “triggers, steps, code, configured props, and control flow”, and that it does not contain their data or credentials. A value that is, or could be, a credential is replaced with <redacted>. Pipedream calls the export a record and a reference for rebuilding elsewhere, not something another platform imports. So the code comes through and the secrets do not.

Left outWhat the export holdsWhat to do
Secret prop values<redacted> in the file; the prop's name is keptCreate each as a repository secret and pass it in the step's env
Connected accountsOnly the account's authProvisionId, which means nothing outside your workspaceCreate a token or an app of your own with each provider; the grant was to Pipedream's app
Environment variablesNot exportedCopy the names and values from your workspace settings while you can
Event historyNot exportedDownload what you need before 30 April 2027
Data stores and File Store filesNot exportedDownload them before 30 April 2027 and keep them where the new step can read them
Code of private multi-file componentsOnly the component's keyKeep your own copy of the source

Also worth knowing

leave-pipedream turns every one of these into a line in MIGRATION.md, with the name of the secret to create for each redacted prop and connected account.

Move a scheduled workflow by hand

For each workflow with a schedule trigger, in a repository of your own on GitHub:

  1. Copy the trigger's cron line and time zone into a workflow file's on.schedule. GitHub takes the time zone as timezone, an IANA name, so the run follows the clock change as it did on Pipedream.
  2. Save each code step from the editor to a file. A Node.js step is export default defineComponent({ async run({ steps, $ }) … }): keep the body of run, read steps.<name> from the step before (pass it in a file), and read secrets from process.env. A Python step's handler(pd) works the same with pd.steps and os.environ.
  3. For every connected account and secret prop, create a token with the app itself and store it under Settings → Secrets and variables → Actions; pass it in the step's env.
  4. Rewrite each pre-built action against the app's own API. Their code is under a license that excludes commercial use: do not copy it.
  5. Run it once by hand, then turn the Pipedream workflow off and merge: GitHub runs a schedule only from the default branch, so the merge is the switch.
# .github/workflows/nightly-sync.yml
name: Nightly sync
on:
  schedule:
    - cron: "30 2 * * *"            # the trigger's schedule, as Pipedream shows it
      timezone: "America/New_York"  # the trigger's time zone
  workflow_dispatch:                # run it by hand to test
permissions:
  contents: read
jobs:
  run:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v7
      - uses: actions/setup-node@v7
        with:
          node-version: "24"
      - run: node steps/fetch.mjs     # step 1, copied from the editor
        env:
          SLACK_TOKEN: ${{ secrets.SLACK_TOKEN }}

leave-pipedream does this for a whole export at once, with a runner that keeps Pipedream's steps and $ so the code runs unchanged; until its repository is published, this is the same move by hand.

An hourly watch that your migrated schedules ran, from outside GitHub's scheduler, is not built.

A migrated schedule runs on GitHub's scheduler, which delays and drops runs under load and sends no alert. A watch would check every hour, from outside it, that each migrated workflow ran, and email you when one is late, missed, or green with nothing done. It does not exist yet. What works today: each converted workflow can ping a heartbeat URL you set, such as a free healthchecks.io check, and didrun reads a repo's scheduled runs when you ask.

I would pay for an hourly watch of my migrated schedules

The click is counted, and nothing else is sent: no form, no email, no cookie. There is no price yet and nothing is charged.

Sources

Not affiliated with Pipedream. Pipedream is named here only to say what these pages and the tool read; the quotes are from Pipedream's own documentation, read on 9 October 2026.