KuKirin BLE protocol lab

G2/G4 Read + Write Lab

Disconnected

Recorder + decoder + controlled write laboratory

Read every mapped field and test exact FFF1 commands with readback verification.

The site subscribes to FFF2, reads the available standard characteristics, records automatically, and exposes simple mode and light controls through FFF1 when the write switch is enabled.

Vehicle under test G4 decoding is enabled. The model is stamped into every exported row.
ServiceFFF0
NotifyFFF2
WriteFFF1not connected
DecoderG4 FFF2 v2
Packets0
RecordingStopped
Capture time00:00
Tests passed0 / 17
DeviceNone
0.0km/h
Peak0.0 km/h
Integrated trip0.000 km
Distance tick delta0.0 km

High confidence

Mapped telemetry

validated map
Ride mode
Battery—%2A19: —
Motor temperature— °CFrame B 0..1 LE
Current / load candidate— AFrame B 8..9 LE ÷100
LightsFrame A offset 17 bit 0
Drive requestFrame A offset 4 bit 1
Brake inputFrame A offset 4 bit 3
Brake output mirrorFrame A offset 14 bit 3

Mode profile

Controller limits

Current/torque ceiling candidateExpected 25 / 30 / 40
Speed-limit codeExpected 20 / 40 / 99
Nominal voltage classExpected 60

Still under investigation

Unknown and lower-confidence fields

do not rename yet
Dynamic byte A8range —
Possible ambient/controller temp A9range —
Static flags A11
Possible fault word A12..13
Output flags A14
Constants A15 / A16

Packet health

Frame families

128-byte startup fills0
20-byte Frame A0
11-byte Frame B0
Unknown lengths0
Last FFF2 packetWaiting…

Guided physical validation

Start a test, perform the action, and let the decoder judge the evidence.

Tests use the G4 FFF2 v2 map only.

Active instruction

No test selected

Choose Start on a test card. The site will add markers automatically.

Simple FFF1 controls

Mode and lights from the passive Frame A.

Three mode buttons and two light buttons. No raw console, no arming ritual.

FFF1Unavailable
WritesOff
Last writeNone

Control switch

Enable mode + light writes

The site clones the latest passive G4 Frame A, changes only the mapped mode or lights bytes, then writes that 20-byte frame once to FFF1.

Explicit BLE reads

Read every available characteristic now

Manufacturer
Model
Serial
Hardware revision
PnP ID

Write evidence

Command and readback results

TimeModelCommandTXExpected readbackResult
No writes sent.

Automatic CSV logging

Waiting for connection

Logging begins when FFF2 notifications start and also records explicit reads and FFF1 writes.

Manual markers

Tap before the action

Live stream

BLE traffic: RX, reads and TX

#TimeModelDirectionSourceFamily / operationHex / marker
No capture yet.

Offline validation

Load an exported CSV on any phone or computer.

The file is processed locally in the browser. Nothing is uploaded.

Loaded file

No CSV loaded

Choose a G4 capture to generate the same telemetry summary and test evidence.

Phone setup

  1. Open the deployed Vercel URL in Safari on the iPhone beside the scooter.
  2. Install and enable the Beacio Safari extension, then reload the page.
  3. Use the normal Safari tab. Do not launch it from a Home Screen shortcut.
  4. Select the correct model before connecting. G2 remains raw-decoded and keeps a separate FFF1 command store, so G2 and G4 cannot mix.
  5. Press Scan and select the scooter. The site opens FFF2 for reads and FFF1 for controlled writes.
  6. Keep both wheels safely clear of the ground for throttle or speed tests.
Write boundary

FFF1 writes use one simple enable switch and only expose mode and light controls. Commands are sent once, never retried, and every TX is logged. The site never accesses TI OAD characteristics.