Welcome, Guest
You have to register before you can post on our site.

Username
  

Password
  





Search Forums

(Advanced Search)

Forum Statistics
» Members: 10,092
» Latest member: PaulWu
» Forum threads: 4,254
» Forum posts: 21,077

Full Statistics

Online Users
There are currently 137 online users.
» 0 Member(s) | 121 Guest(s)
AhrefsBot, Applebot, Baidu, Bytespider, Crawl, Google, PetalBot, bot

Latest Threads
KC868-HAv2 phantom press ...
Forum: KC868-HA /HA v2
Last Post: phrfpeixoto
Yesterday, 01:57 AM
» Replies: 2
» Views: 1,478
KC868-A6 Analog inputs
Forum: KC868-A6
Last Post: Tomas4289
09-28-2026, 12:57 PM
» Replies: 2
» Views: 33
N60/N30/N20/N10 PC softwa...
Forum: N10
Last Post: admin
09-28-2026, 12:49 PM
» Replies: 13
» Views: 1,627
getting the A8A inputs to...
Forum: Development
Last Post: admin
09-28-2026, 08:38 AM
» Replies: 5
» Views: 204
Best way to read from N30
Forum: N30
Last Post: admin
09-27-2026, 12:20 AM
» Replies: 3
» Views: 48
extend KC868-A16v3
Forum: KC868-A series and Uair Smart Controller
Last Post: bitet96717
09-24-2026, 06:41 AM
» Replies: 2
» Views: 241
Las Firmware ?
Forum: KC868-A16
Last Post: admin
09-22-2026, 11:15 PM
» Replies: 8
» Views: 946
kc868-a6 analog input
Forum: KC868-A6
Last Post: admin
09-21-2026, 11:38 PM
» Replies: 1
» Views: 148
A32 pro tuya
Forum: "KCS" v3 firmware
Last Post: admin
09-21-2026, 11:38 PM
» Replies: 1
» Views: 71
Disconnect loop with Home...
Forum: F16
Last Post: admin
09-21-2026, 01:16 AM
» Replies: 3
» Views: 133

  Automatic water Level Controller
Posted by: unais - 06-10-2026, 01:46 PM - Forum: Apply for free sample product - No Replies

Hi Team

I'm currently researching for a Water Controller System. So i need a main controller to research. If it works better, useful for the community. 
This is a fully automated water level controller and monitoring system with advanced systems. So if you support me, i can build a solution for that.

Print this item

  M16v2 and SCT013-050
Posted by: SixSixOne - 06-10-2026, 10:20 AM - Forum: KC868-M16 / M1 / MB / M30 - Replies (5)

Dear Sir,
I have bought a M16v2 recently and try to make it work with SCT013-050 50A/1V sensors (https://www.aliexpress.com/item/10050092...1802lqJyc9) with the jumper positioned in the "V" measurement on the board.

I've used the last yaml code you provided (also attached) however it is not measuring anything.

My house has 3 phases and I have already checked all 3 phases as they are coming from teh grid as well as from a socket.
I've never received any measurement the Amperage is always 0A and the RAW measurements 0.11A, 0.12A, 0.13A


Any idea what is going on? 

Tks a lot



Attached Files
.txt   Kincony-m16-v2.txt (Size: 9.86 KB / Downloads: 123)
Print this item

Wink Single-family home automation
Posted by: Jan_W - 06-09-2026, 01:53 PM - Forum: DIY Project - Replies (3)

I'll show off a project that's currently underway - full home automation: 
- lighting (including dimmable LEDs)
- blinds, multi device control: fans, pumps
- energy measurement, 
- temperature and humidity sensors
- and much more Smile

3x B32M
1x DM16
1x G1
1x N20

[Image: tqglEM0.jpeg]

Print this item

  connect 2 KC868 to homeassistant with mqtt broker Mosquitto
Posted by: guycaluwaerts - 06-09-2026, 08:33 AM - Forum: KC868-A16 - Replies (5)

Dear,

I try to integrate 2 Kincony boards ( KC868-A16 an KC868-AP) in Homeassistant by mqtt broker Mosquitto.

For the board kc868-A16 I made the correct settings I think.

Mqtt : enable
broker address : mqtt://192.168.0.157
broker port : 1883
broker username : mqtt
broker password : 123

In the screen ' monitor' : status mqtt : connected.

My problem is the integration in homeassistant. I followed your tutorial, but at step 3, I don't understand how you imported the yaml files of your boards in the file editor.
Is it possible to explain how to import the yaml files for the boards KC868-A16 and KC868-AP ?

Second question : When I connect the secondboard ( KC868-AP), can I use the same settings for the mqtt broker ?



Attached Files Thumbnail(s)
   
Image(s)
       
Print this item

  KC868-A8 OpenPLC Function Blocks for Digital input
Posted by: admin - 06-09-2026, 12:00 AM - Forum: KC868-A8 - No Replies

Code:
#include <Arduino.h>
//#include <Wire.h>
#include <PCF8574.h>

// PCF8574 input address
#define I2C_INPUTS_ADR 0x22

PCF8574 pcf_in(I2C_INPUTS_ADR);

void setup()
{
    // ESP32 KC868 default I2C pins
    Wire.begin(4, 5); // SDA, SCL

    // Initialize PCF8574
    pcf_in.begin();

    // Configure PCF8574 pins as inputs
    pcf_in.pinMode(P0, INPUT);
    pcf_in.pinMode(P1, INPUT);
    pcf_in.pinMode(P2, INPUT);
    pcf_in.pinMode(P3, INPUT);
    pcf_in.pinMode(P4, INPUT);
    pcf_in.pinMode(P5, INPUT);
    pcf_in.pinMode(P6, INPUT);
    pcf_in.pinMode(P7, INPUT);

}

void loop()
{
    // KC868 inputs are active LOW
    IN_0 = (pcf_in.digitalRead(P0) == LOW);
    IN_1 = (pcf_in.digitalRead(P1) == LOW);
    IN_2 = (pcf_in.digitalRead(P2) == LOW);
    IN_3 = (pcf_in.digitalRead(P3) == LOW);
    IN_4 = (pcf_in.digitalRead(P4) == LOW);
    IN_5 = (pcf_in.digitalRead(P5) == LOW);
    IN_6 = (pcf_in.digitalRead(P6) == LOW);
    IN_7 = (pcf_in.digitalRead(P7) == LOW);
}
   

Print this item

  INCREMENTAL ENCODER
Posted by: fabuena - 06-08-2026, 10:04 PM - Forum: KC868-A8 - Replies (3)

Hello, 
I want to connect a CALT GHW38 incremental encoder with a built-in measuring wheel to my KC 868-A8 in the simplest way possible. 
Should I get an NPN, PNP, or 5V line driver encoder? 
Dispositivo de Medición de Longitud CALT GHW38, Codificador Rotatorio con Salida de Pulso, con Rueda Antideslizante de 200 mm/300 mm de Circunferencia - AliExpress

Which inputs do I connect signals A and B to?

Thanks

Print this item

  "KCS" v3 Nx energy meter RS485 TCP/IP Modbus protocol document
Posted by: admin - 06-07-2026, 01:39 AM - Forum: "KCS" v3 firmware - No Replies

"KCS" v3 Nx energy meter RS485 TCP/IP Modbus protocol document:



Attached Files
.txt   n10_energy_modbus_protocol_20260324.txt (Size: 11.98 KB / Downloads: 155)
.txt   n20_energy_modbus_protocol_20260324.txt (Size: 13.6 KB / Downloads: 157)
.txt   n30_energy_modbus_protocol_20260324.txt (Size: 15.9 KB / Downloads: 143)
.txt   n60_energy_modbus_protocol_20260324.txt (Size: 12.18 KB / Downloads: 137)
Print this item

  "KCS" v3 TCP/IP Standard Modbus protocol document
Posted by: admin - 06-07-2026, 01:36 AM - Forum: "KCS" v3 firmware - No Replies

KCS protocol webpage, "TCP Server" = "Modbus TCP". it's a standard modbus protocol.

Code:
KCSv3 Modbus TCP Protocol Specification
=======================================

1. Overview
-----------

This document specifies the standard Modbus TCP protocol exposed by the
KCSv3 firmware TCP server.

This mode uses the standard Modbus TCP ADU with an MBAP header. It does not use
the RTU CRC field.

2. Communication Parameters
---------------------------

- Protocol: Standard Modbus TCP
- TCP port: configured by tcp_server_port
- Unit ID: configured by tcp_server_protocol_modbus_local_addr
- Register addressing: 0-based Modbus protocol address
- Frame format: [MBAP Header][PDU]
- Protocol ID in MBAP: 0x0000
- CRC: not used

MBAP header format:

+--------+----------------+----------------------------------------------+
| Bytes  | Field          | Description                                  |
+--------+----------------+----------------------------------------------+
| 0..1   | Transaction ID | Echoed in the response                       |
| 2..3   | Protocol ID    | Must be 0x0000                               |
| 4..5   | Length         | Unit ID byte + PDU length                    |
| 6      | Unit ID        | Must match tcp_server_protocol_modbus_local_addr |
+--------+----------------+----------------------------------------------+

The firmware validates the MBAP Protocol ID, Length, and Unit ID before
processing the PDU. Responses are sent only to the requesting TCP client.

3. Supported Function Codes
---------------------------

+---------------+---------------------------+-------------------------------+
| Function Code | Name                      | Usage                         |
+---------------+---------------------------+-------------------------------+
| 0x01          | Read Coils                | Read DO output state          |
| 0x02          | Read Discrete Inputs      | Read DI input state           |
| 0x03          | Read Holding Registers    | Read DAC/IR/RF/energy data    |
| 0x04          | Read Input Registers      | Read ADC/temperature/humidity |
| 0x05          | Write Single Coil         | Set one DO or trigger toggle  |
| 0x06          | Write Single Register     | Set DAC or trigger IR/RF      |
| 0x0F          | Write Multiple Coils      | Set multiple DO channels      |
| 0x10          | Write Multiple Registers  | Set multiple DAC channels     |
+---------------+---------------------------+-------------------------------+

4. Addressing Notes
-------------------

All addresses in this document are 0-based Modbus protocol addresses.

Examples:

- Holding register address 100 is sent as 0x0064 in the Modbus PDU.
- In pymodbus, use read_holding_registers(100, count=2, slave=<unit_id>).
- Some Modbus tools display holding register 100 as 40101 or similar. Use the
  tool's 0-based/1-based setting carefully.

5. Coils (Function Codes 0x01, 0x05, 0x0F)
-------------------------------------------

5.1 DO Output State and Control
-------------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DO_NUM-1          | DO output channels   | 0x01 read, 0x05/0x0F write  |
+------------------------+----------------------+-----------------------------+

Write value for function code 0x05:

- 0xFF00: turn ON
- 0x0000: turn OFF

Function code 0x0F supports only the normal DO output range starting at address
0.

5.2 DO Toggle Control
---------------------

+-----------------------------+----------------------+--------------------------+
| Address Range               | Description          | Access                   |
+-----------------------------+----------------------+--------------------------+
| 0x0100 .. 0x0100+DO_NUM-1   | Toggle DO channels   | 0x05 write only          |
+-----------------------------+----------------------+--------------------------+

Write 0xFF00 to address 0x0100 + channel_index to toggle that output channel.
Writing 0x0000 is accepted but does not toggle the output.

6. Discrete Inputs (Function Code 0x02)
---------------------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DI_NUM-1          | DI input channels    | 0x02 read                   |
+------------------------+----------------------+-----------------------------+

DI inputs are active-low in the firmware mapping:

- Hardware low / active input returns 1
- Hardware high / inactive input returns 0

7. Holding Registers (Function Codes 0x03, 0x06, 0x10)
------------------------------------------------------

7.1 DAC Output Registers
------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DAC_NUM-1         | DAC output channels  | 0x03 read, 0x06/0x10 write  |
+------------------------+----------------------+-----------------------------+

DAC write value range: 0 .. 255.

Function code 0x10 supports only this DAC register range.

7.2 IR/RF Control Registers
---------------------------

+----------+-------------+----------------------+-----------------------------+
| Address  | Name        | Description          | Access                      |
+----------+-------------+----------------------+-----------------------------+
| 0x0040   | IR_SEND     | Send learned IR slot | 0x03 read, 0x06 write       |
| 0x0041   | IR_LEARN    | Learn IR slot/port   | 0x03 read, 0x06 write       |
| 0x0042   | IR_DELETE   | Delete IR slot       | 0x03 read, 0x06 write       |
| 0x0050   | RF_SEND     | Send learned RF slot | 0x03 read, 0x06 write       |
+----------+-------------+----------------------+-----------------------------+

IR_SEND:

- Value: IR memory slot index
- Valid range: 0 .. IR_MEM_NUM-1

IR_LEARN:

- High byte: IR memory slot index
- Low byte: IR send port number, starting from 1

IR_DELETE:

- Value: IR memory slot index
- Valid range: 0 .. IR_MEM_NUM-1

RF_SEND:

- Value: RF memory slot index
- The selected RF slot must exist and be learned

These registers exist only on board variants with the corresponding IR/RF
feature enabled. Otherwise accesses return an illegal data address exception.

7.3 Energy Measurement Registers
--------------------------------

Energy data is exposed as read-only Holding Registers and is read with function
code 0x03.

Each energy chip uses 68 holding registers. The base address is:

  base = 100 + chip_index * 100

where chip_index starts from 0.

+--------------+----------------+----------------+--------------------------+
| Offset Range | Parameter      | Format         | Resolution / Notes       |
+--------------+----------------+----------------+--------------------------+
| 0 .. 19      | RMS_1..RMS_10  | uint32 CDAB    | Current in A * 1000      |
| 20 .. 39     | WATT_1..WATT_10| int32 CDAB     | Power in W * 10          |
| 40 .. 59     | Energy_1..10   | float32 CDAB   | Energy in kWh            |
| 60 .. 61     | Energy_Sum     | float32 CDAB   | Total energy in kWh      |
| 62           | RMS_V          | uint16         | Voltage in V * 100       |
| 63           | Period         | uint16         | Frequency in Hz * 100    |
| 64 .. 65     | TPS1           | float32 CDAB   | Temperature in deg C     |
| 66 .. 67     | PF             | float32 CDAB   | Power factor             |
+--------------+----------------+----------------+--------------------------+

Per-channel offsets:

+----------------+----------------+----------------+--------------------------+
| Channel        | Current Offset | Power Offset   | Energy Offset            |
+----------------+----------------+----------------+--------------------------+
| 1              | 0              | 20             | 40                       |
| 2              | 2              | 22             | 42                       |
| 3              | 4              | 24             | 44                       |
| 4              | 6              | 26             | 46                       |
| 5              | 8              | 28             | 48                       |
| 6              | 10             | 30             | 50                       |
| 7              | 12             | 32             | 52                       |
| 8              | 14             | 34             | 54                       |
| 9              | 16             | 36             | 56                       |
| 10             | 18             | 38             | 58                       |
+----------------+----------------+----------------+--------------------------+

For 32-bit integer and float values, read two consecutive registers. The lower
16-bit word is returned first, followed by the upper 16-bit word.

Examples:

- Chip 1 current channel 1: read holding registers 100 and 101
- Chip 2 power channel 1: read holding registers 220 and 221
- Chip 1 voltage: read holding register 162
- Chip 1 frequency: read holding register 163

8. Input Registers (Function Code 0x04)
---------------------------------------

+-------------------------------+----------------------+--------------------------+
| Address Range                 | Description          | Format                   |
+-------------------------------+----------------------+--------------------------+
| 0 .. ADC_NUM-1                | ADC input channels   | uint16 raw ADC value     |
| 0x0100 .. 0x0100+SENSOR_NUM-1 | Temperature sensors  | int16, deg C * 10        |
| 0x0120 .. 0x0120+SENSOR_NUM-1 | Humidity sensors     | int16, %RH * 10          |
+-------------------------------+----------------------+--------------------------+

If a temperature or humidity sensor is invalid or not present, the returned
value is 0x7FFF.

9. Board-Dependent Limits
-------------------------

The following symbols depend on the compiled board model:

- DO_NUM: number of digital outputs
- DI_NUM: number of digital inputs
- DAC_NUM: number of DAC outputs
- ADC_NUM: number of ADC inputs
- SENSOR_NUM: maximum temperature/humidity sensor slots
- ENERGY_NUM: number of energy measurement chips

N-series energy chip bases:

+-------+------------+--------------------------------------+
| Board | ENERGY_NUM | Energy Holding Register Bases        |
+-------+------------+--------------------------------------+
| N10   | 1          | 100                                  |
| N20   | 2          | 100, 200                             |
| N30   | 3          | 100, 200, 300                        |
| N60   | 6          | 100, 200, 300, 400, 500, 600         |
+-------+------------+--------------------------------------+

10. Exception Codes
-------------------

+----------------+----------------------------+-------------------------------+
| Exception Code | Name                       | Meaning                       |
+----------------+----------------------------+-------------------------------+
| 0x01           | Illegal Function           | Unsupported function code     |
| 0x02           | Illegal Data Address       | Unsupported address/range     |
| 0x03           | Illegal Data Value         | Invalid value or quantity     |
| 0x04           | Slave Device Failure       | Runtime failure or overflow   |
+----------------+----------------------------+-------------------------------+

11. Request Size Limits
-----------------------

- Read coils/discrete inputs: quantity 1 .. 2000
- Read holding/input registers: quantity 1 .. 125
- Write multiple coils: quantity 1 .. 1968
- Write multiple registers: quantity 1 .. 123
download protocol:

.txt   Modbus_TCP_Protocol.txt (Size: 11.59 KB / Downloads: 171)

Print this item

  "KCS" v3 Modbus RTU over TCP/IP protocol document
Posted by: admin - 06-07-2026, 01:33 AM - Forum: "KCS" v3 firmware - No Replies

KCS protocol webpage, "TCP Server" = "Modbus-RTU-V2". Just RS485 modbus protocol over TCP/IP.

Code:
KCSv3 Modbus RTU over TCP Protocol Specification
================================================

1. Overview
-----------

This document specifies the Modbus RTU over TCP protocol exposed by the
KCSv3 firmware TCP server when the TCP protocol mode is configured for Modbus RTU
frames.

This mode transports a complete Modbus RTU ADU over a TCP socket. It does not use
the standard Modbus TCP MBAP header.

2. Communication Parameters
---------------------------

- Protocol: Modbus RTU ADU transported over TCP
- TCP port: configured by tcp_server_port
- Slave address: configured by tcp_server_protocol_modbus_local_addr
- Register addressing: 0-based Modbus protocol address
- Frame format: [Slave Address][PDU][CRC Lo][CRC Hi]
- CRC: Modbus CRC16, low byte first
- MBAP header: not used

Clients should send one complete RTU ADU frame per TCP request. The firmware
validates the RTU slave address and CRC before processing the PDU.

3. Supported Function Codes
---------------------------

+---------------+---------------------------+-------------------------------+
| Function Code | Name                      | Usage                         |
+---------------+---------------------------+-------------------------------+
| 0x01          | Read Coils                | Read DO output state          |
| 0x02          | Read Discrete Inputs      | Read DI input state           |
| 0x03          | Read Holding Registers    | Read DAC/IR/RF/energy data    |
| 0x04          | Read Input Registers      | Read ADC/temperature/humidity |
| 0x05          | Write Single Coil         | Set one DO or trigger toggle  |
| 0x06          | Write Single Register     | Set DAC or trigger IR/RF      |
| 0x0F          | Write Multiple Coils      | Set multiple DO channels      |
| 0x10          | Write Multiple Registers  | Set multiple DAC channels     |
+---------------+---------------------------+-------------------------------+

4. Addressing Notes
-------------------

All addresses in this document are 0-based Modbus protocol addresses.

Examples:

- Holding register address 100 is sent as 0x0064 in the Modbus PDU.
- Some Modbus tools display holding register 100 as 40101 or similar. Use the
  tool's 0-based/1-based setting carefully.

5. Coils (Function Codes 0x01, 0x05, 0x0F)
-------------------------------------------

5.1 DO Output State and Control
-------------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DO_NUM-1          | DO output channels   | 0x01 read, 0x05/0x0F write  |
+------------------------+----------------------+-----------------------------+

Write value for function code 0x05:

- 0xFF00: turn ON
- 0x0000: turn OFF

Function code 0x0F supports only the normal DO output range starting at address
0.

5.2 DO Toggle Control
---------------------

+-----------------------------+----------------------+--------------------------+
| Address Range               | Description          | Access                   |
+-----------------------------+----------------------+--------------------------+
| 0x0100 .. 0x0100+DO_NUM-1   | Toggle DO channels   | 0x05 write only          |
+-----------------------------+----------------------+--------------------------+

Write 0xFF00 to address 0x0100 + channel_index to toggle that output channel.
Writing 0x0000 is accepted but does not toggle the output.

6. Discrete Inputs (Function Code 0x02)
---------------------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DI_NUM-1          | DI input channels    | 0x02 read                   |
+------------------------+----------------------+-----------------------------+

DI inputs are active-low in the firmware mapping:

- Hardware low / active input returns 1
- Hardware high / inactive input returns 0

7. Holding Registers (Function Codes 0x03, 0x06, 0x10)
------------------------------------------------------

7.1 DAC Output Registers
------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DAC_NUM-1         | DAC output channels  | 0x03 read, 0x06/0x10 write  |
+------------------------+----------------------+-----------------------------+

DAC write value range: 0 .. 255.

Function code 0x10 supports only this DAC register range.

7.2 IR/RF Control Registers
---------------------------

+----------+-------------+----------------------+-----------------------------+
| Address  | Name        | Description          | Access                      |
+----------+-------------+----------------------+-----------------------------+
| 0x0040   | IR_SEND     | Send learned IR slot | 0x03 read, 0x06 write       |
| 0x0041   | IR_LEARN    | Learn IR slot/port   | 0x03 read, 0x06 write       |
| 0x0042   | IR_DELETE   | Delete IR slot       | 0x03 read, 0x06 write       |
| 0x0050   | RF_SEND     | Send learned RF slot | 0x03 read, 0x06 write       |
+----------+-------------+----------------------+-----------------------------+

IR_SEND:

- Value: IR memory slot index
- Valid range: 0 .. IR_MEM_NUM-1

IR_LEARN:

- High byte: IR memory slot index
- Low byte: IR send port number, starting from 1

IR_DELETE:

- Value: IR memory slot index
- Valid range: 0 .. IR_MEM_NUM-1

RF_SEND:

- Value: RF memory slot index
- The selected RF slot must exist and be learned

These registers exist only on board variants with the corresponding IR/RF
feature enabled. Otherwise accesses return an illegal data address exception.

7.3 Energy Measurement Registers
--------------------------------

Energy data is exposed as read-only Holding Registers and is read with function
code 0x03.

Each energy chip uses 68 holding registers. The base address is:

  base = 100 + chip_index * 100

where chip_index starts from 0.

+--------------+----------------+----------------+--------------------------+
| Offset Range | Parameter      | Format         | Resolution / Notes       |
+--------------+----------------+----------------+--------------------------+
| 0 .. 19      | RMS_1..RMS_10  | uint32 CDAB    | Current in A * 1000      |
| 20 .. 39     | WATT_1..WATT_10| int32 CDAB     | Power in W * 10          |
| 40 .. 59     | Energy_1..10   | float32 CDAB   | Energy in kWh            |
| 60 .. 61     | Energy_Sum     | float32 CDAB   | Total energy in kWh      |
| 62           | RMS_V          | uint16         | Voltage in V * 100       |
| 63           | Period         | uint16         | Frequency in Hz * 100    |
| 64 .. 65     | TPS1           | float32 CDAB   | Temperature in deg C     |
| 66 .. 67     | PF             | float32 CDAB   | Power factor             |
+--------------+----------------+----------------+--------------------------+

Per-channel offsets:

+----------------+----------------+----------------+--------------------------+
| Channel        | Current Offset | Power Offset   | Energy Offset            |
+----------------+----------------+----------------+--------------------------+
| 1              | 0              | 20             | 40                       |
| 2              | 2              | 22             | 42                       |
| 3              | 4              | 24             | 44                       |
| 4              | 6              | 26             | 46                       |
| 5              | 8              | 28             | 48                       |
| 6              | 10             | 30             | 50                       |
| 7              | 12             | 32             | 52                       |
| 8              | 14             | 34             | 54                       |
| 9              | 16             | 36             | 56                       |
| 10             | 18             | 38             | 58                       |
+----------------+----------------+----------------+--------------------------+

For 32-bit integer and float values, read two consecutive registers. The lower
16-bit word is returned first, followed by the upper 16-bit word.

Examples:

- Chip 1 current channel 1: read holding registers 100 and 101
- Chip 2 power channel 1: read holding registers 220 and 221
- Chip 1 voltage: read holding register 162
- Chip 1 frequency: read holding register 163

8. Input Registers (Function Code 0x04)
---------------------------------------

+-------------------------------+----------------------+--------------------------+
| Address Range                 | Description          | Format                   |
+-------------------------------+----------------------+--------------------------+
| 0 .. ADC_NUM-1                | ADC input channels   | uint16 raw ADC value     |
| 0x0100 .. 0x0100+SENSOR_NUM-1 | Temperature sensors  | int16, deg C * 10        |
| 0x0120 .. 0x0120+SENSOR_NUM-1 | Humidity sensors     | int16, %RH * 10          |
+-------------------------------+----------------------+--------------------------+

If a temperature or humidity sensor is invalid or not present, the returned
value is 0x7FFF.

9. Board-Dependent Limits
-------------------------

The following symbols depend on the compiled board model:

- DO_NUM: number of digital outputs
- DI_NUM: number of digital inputs
- DAC_NUM: number of DAC outputs
- ADC_NUM: number of ADC inputs
- SENSOR_NUM: maximum temperature/humidity sensor slots
- ENERGY_NUM: number of energy measurement chips

N-series energy chip bases:

+-------+------------+--------------------------------------+
| Board | ENERGY_NUM | Energy Holding Register Bases        |
+-------+------------+--------------------------------------+
| N10   | 1          | 100                                  |
| N20   | 2          | 100, 200                             |
| N30   | 3          | 100, 200, 300                        |
| N60   | 6          | 100, 200, 300, 400, 500, 600         |
+-------+------------+--------------------------------------+

10. Exception Codes
-------------------

+----------------+----------------------------+-------------------------------+
| Exception Code | Name                       | Meaning                       |
+----------------+----------------------------+-------------------------------+
| 0x01           | Illegal Function           | Unsupported function code     |
| 0x02           | Illegal Data Address       | Unsupported address/range     |
| 0x03           | Illegal Data Value         | Invalid value or quantity     |
| 0x04           | Slave Device Failure       | Runtime failure or overflow   |
+----------------+----------------------------+-------------------------------+

11. Request Size Limits
-----------------------

- Read coils/discrete inputs: quantity 1 .. 2000
- Read holding/input registers: quantity 1 .. 125
- Write multiple coils: quantity 1 .. 1968
- Write multiple registers: quantity 1 .. 123
download protocol:

.txt   Modbus_RTU_over_TCP_Protocol.txt (Size: 11.05 KB / Downloads: 155)

Print this item

  "KCS" v3 RS485 Standard Modbus protocol document
Posted by: admin - 06-07-2026, 01:28 AM - Forum: "KCS" v3 firmware - No Replies

KCS protocol webpage, set to "Modbus_RTU-v2" option. it's a standard modbus protocol.

Code:
KCSv3 Modbus RTU Protocol Specification
=======================================

1. Overview
-----------

This document specifies the Modbus RTU protocol exposed by the KCSv3
firmware on the RS485 interface.

2. Communication Parameters
---------------------------

- Protocol: Modbus RTU
- Physical interface: RS485
- Slave address: configured by rs485_local_addr
- Register addressing: 0-based Modbus protocol address
- Frame format: [Slave Address][PDU][CRC Lo][CRC Hi]
- CRC: Modbus CRC16, low byte first

Serial port parameters are configured by the firmware RS485 settings.

3. Supported Function Codes
---------------------------

+---------------+---------------------------+-------------------------------+
| Function Code | Name                      | Usage                         |
+---------------+---------------------------+-------------------------------+
| 0x01          | Read Coils                | Read DO output state          |
| 0x02          | Read Discrete Inputs      | Read DI input state           |
| 0x03          | Read Holding Registers    | Read DAC/IR/RF/energy data    |
| 0x04          | Read Input Registers      | Read ADC/temperature/humidity |
| 0x05          | Write Single Coil         | Set one DO or trigger toggle  |
| 0x06          | Write Single Register     | Set DAC or trigger IR/RF      |
| 0x0F          | Write Multiple Coils      | Set multiple DO channels      |
| 0x10          | Write Multiple Registers  | Set multiple DAC channels     |
+---------------+---------------------------+-------------------------------+

4. Addressing Notes
-------------------

All addresses in this document are 0-based Modbus protocol addresses.

Examples:

- Holding register address 100 is sent as 0x0064 in the Modbus PDU.
- Some Modbus tools display holding register 100 as 40101 or similar. Use the
  tool's 0-based/1-based setting carefully.

5. Coils (Function Codes 0x01, 0x05, 0x0F)
-------------------------------------------

5.1 DO Output State and Control
-------------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DO_NUM-1          | DO output channels   | 0x01 read, 0x05/0x0F write  |
+------------------------+----------------------+-----------------------------+

Write value for function code 0x05:

- 0xFF00: turn ON
- 0x0000: turn OFF

Function code 0x0F supports only the normal DO output range starting at address
0.

5.2 DO Toggle Control
---------------------

+-----------------------------+----------------------+--------------------------+
| Address Range               | Description          | Access                   |
+-----------------------------+----------------------+--------------------------+
| 0x0100 .. 0x0100+DO_NUM-1   | Toggle DO channels   | 0x05 write only          |
+-----------------------------+----------------------+--------------------------+

Write 0xFF00 to address 0x0100 + channel_index to toggle that output channel.
Writing 0x0000 is accepted but does not toggle the output.

6. Discrete Inputs (Function Code 0x02)
---------------------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DI_NUM-1          | DI input channels    | 0x02 read                   |
+------------------------+----------------------+-----------------------------+

DI inputs are active-low in the firmware mapping:

- Hardware low / active input returns 1
- Hardware high / inactive input returns 0

7. Holding Registers (Function Codes 0x03, 0x06, 0x10)
------------------------------------------------------

7.1 DAC Output Registers
------------------------

+------------------------+----------------------+-----------------------------+
| Address Range          | Description          | Access                      |
+------------------------+----------------------+-----------------------------+
| 0 .. DAC_NUM-1         | DAC output channels  | 0x03 read, 0x06/0x10 write  |
+------------------------+----------------------+-----------------------------+

DAC write value range: 0 .. 255.

Function code 0x10 supports only this DAC register range.

7.2 IR/RF Control Registers
---------------------------

+----------+-------------+----------------------+-----------------------------+
| Address  | Name        | Description          | Access                      |
+----------+-------------+----------------------+-----------------------------+
| 0x0040   | IR_SEND     | Send learned IR slot | 0x03 read, 0x06 write       |
| 0x0041   | IR_LEARN    | Learn IR slot/port   | 0x03 read, 0x06 write       |
| 0x0042   | IR_DELETE   | Delete IR slot       | 0x03 read, 0x06 write       |
| 0x0050   | RF_SEND     | Send learned RF slot | 0x03 read, 0x06 write       |
+----------+-------------+----------------------+-----------------------------+

IR_SEND:

- Value: IR memory slot index
- Valid range: 0 .. IR_MEM_NUM-1

IR_LEARN:

- High byte: IR memory slot index
- Low byte: IR send port number, starting from 1

IR_DELETE:

- Value: IR memory slot index
- Valid range: 0 .. IR_MEM_NUM-1

RF_SEND:

- Value: RF memory slot index
- The selected RF slot must exist and be learned

These registers exist only on board variants with the corresponding IR/RF
feature enabled. Otherwise accesses return an illegal data address exception.

7.3 Energy Measurement Registers
--------------------------------

Energy data is exposed as read-only Holding Registers and is read with function
code 0x03.

Each energy chip uses 68 holding registers. The base address is:

  base = 100 + chip_index * 100

where chip_index starts from 0.

+--------------+----------------+----------------+--------------------------+
| Offset Range | Parameter      | Format         | Resolution / Notes       |
+--------------+----------------+----------------+--------------------------+
| 0 .. 19      | RMS_1..RMS_10  | uint32 CDAB    | Current in A * 1000      |
| 20 .. 39     | WATT_1..WATT_10| int32 CDAB     | Power in W * 10          |
| 40 .. 59     | Energy_1..10   | float32 CDAB   | Energy in kWh            |
| 60 .. 61     | Energy_Sum     | float32 CDAB   | Total energy in kWh      |
| 62           | RMS_V          | uint16         | Voltage in V * 100       |
| 63           | Period         | uint16         | Frequency in Hz * 100    |
| 64 .. 65     | TPS1           | float32 CDAB   | Temperature in deg C     |
| 66 .. 67     | PF             | float32 CDAB   | Power factor             |
+--------------+----------------+----------------+--------------------------+

Per-channel offsets:

+----------------+----------------+----------------+--------------------------+
| Channel        | Current Offset | Power Offset   | Energy Offset            |
+----------------+----------------+----------------+--------------------------+
| 1              | 0              | 20             | 40                       |
| 2              | 2              | 22             | 42                       |
| 3              | 4              | 24             | 44                       |
| 4              | 6              | 26             | 46                       |
| 5              | 8              | 28             | 48                       |
| 6              | 10             | 30             | 50                       |
| 7              | 12             | 32             | 52                       |
| 8              | 14             | 34             | 54                       |
| 9              | 16             | 36             | 56                       |
| 10             | 18             | 38             | 58                       |
+----------------+----------------+----------------+--------------------------+

For 32-bit integer and float values, read two consecutive registers. The lower
16-bit word is returned first, followed by the upper 16-bit word.

Examples:

- Chip 1 current channel 1: read holding registers 100 and 101
- Chip 2 power channel 1: read holding registers 220 and 221
- Chip 1 voltage: read holding register 162
- Chip 1 frequency: read holding register 163

8. Input Registers (Function Code 0x04)
---------------------------------------

+-------------------------------+----------------------+--------------------------+
| Address Range                 | Description          | Format                   |
+-------------------------------+----------------------+--------------------------+
| 0 .. ADC_NUM-1                | ADC input channels   | uint16 raw ADC value     |
| 0x0100 .. 0x0100+SENSOR_NUM-1 | Temperature sensors  | int16, deg C * 10        |
| 0x0120 .. 0x0120+SENSOR_NUM-1 | Humidity sensors     | int16, %RH * 10          |
+-------------------------------+----------------------+--------------------------+

If a temperature or humidity sensor is invalid or not present, the returned
value is 0x7FFF.

9. Board-Dependent Limits
-------------------------

The following symbols depend on the compiled board model:

- DO_NUM: number of digital outputs
- DI_NUM: number of digital inputs
- DAC_NUM: number of DAC outputs
- ADC_NUM: number of ADC inputs
- SENSOR_NUM: maximum temperature/humidity sensor slots
- ENERGY_NUM: number of energy measurement chips

N-series energy chip bases:

+-------+------------+--------------------------------------+
| Board | ENERGY_NUM | Energy Holding Register Bases        |
+-------+------------+--------------------------------------+
| N10   | 1          | 100                                  |
| N20   | 2          | 100, 200                             |
| N30   | 3          | 100, 200, 300                        |
| N60   | 6          | 100, 200, 300, 400, 500, 600         |
+-------+------------+--------------------------------------+

10. Exception Codes
-------------------

+----------------+----------------------------+-------------------------------+
| Exception Code | Name                       | Meaning                       |
+----------------+----------------------------+-------------------------------+
| 0x01           | Illegal Function           | Unsupported function code     |
| 0x02           | Illegal Data Address       | Unsupported address/range     |
| 0x03           | Illegal Data Value         | Invalid value or quantity     |
| 0x04           | Slave Device Failure       | Runtime failure or overflow   |
+----------------+----------------------------+-------------------------------+

11. Request Size Limits
-----------------------

- Read coils/discrete inputs: quantity 1 .. 2000
- Read holding/input registers: quantity 1 .. 125
- Write multiple coils: quantity 1 .. 1968
- Write multiple registers: quantity 1 .. 123
download protocol:

.txt   Modbus_RTU_Protocol.txt (Size: 10.7 KB / Downloads: 173)

Print this item