KuKirin BLE protocol lab
G2 / G2 Ultra / G4 Read + Write Lab
Recorder + decoder + controlled write laboratory
Read every mapped field and test exact FFF1 commands with readback verification.
The site subscribes to FFF2, decodes mapped G2/G4 fields, records G2 Ultra packets raw until they are mapped,
and exposes direct mode, zero-start, speed/power-curve, speed-config and factory-reset commands through FFF1 behind one switch. Lights remain readable; the uploaded APK proved the old F04C02xx “light” guess was actually zero-start.
G4 display calibration v2: BLE ÷16 remains the raw wheel-speed source. The main gauge is unchanged through 15 km/h, then applies the latest tester-derived correction: roughly 2 km/h correction near 20, ramping toward ~6 km/h at the top of the unloaded run. Raw BLE speed is always shown and exported.
High confidence
Mapped telemetry
Mode profile
Controller limits
Still under investigation
Unknown and lower-confidence fields
Packet health
Frame families
Waiting…Guided physical validation
Start a test, perform the action, and let the decoder judge the evidence.
Guided validation starts with the G4 profile map.
Active instruction
No test selected
Choose Start on a test card. The site will add markers automatically.
Direct FFF1 controls
Mode, zero-start, speed/power curves, speed config, and recovery.
Direct F0 command frames. One write-enable switch; no phrase, timer, checklist, or passive-frame replay.
Correction from reset.apk: F0 4C 02 00/01 belongs to ControlPresenter.zeroStart. The old light-write guess is removed; light state is still read from FFF2.
Control switch
Enable direct FFF1 writes
Once enabled, the controls are writable immediately. Commands are sent once with no automatic retry. The red reset control is a FACTORY RESET.
Manual transport lab
Send raw FFF1 HEX once
Manual transport test: enter raw hex for FFF1. It is sent exactly once and logged.
Explicit BLE reads
Read every available characteristic now
Write evidence
Command and readback results
| Time | Model | Command | TX | Expected readback | Result |
|---|---|---|---|---|---|
| No writes sent. | |||||
Automatic CSV logging
Waiting for connection
Logging begins when FFF2 notifications start and also records explicit reads and FFF1 writes.
Manual markers
Tap before the action
| # | Time | Model | Direction | Source | Family / operation | Hex / marker |
|---|---|---|---|---|---|---|
| No capture yet. | ||||||
Offline validation
Load an exported CSV on any phone or computer.
The file is processed locally in the browser. Nothing is uploaded.
Loaded file
No CSV loaded
Choose a G2, G2 Ultra or G4 CSV. G2 Ultra captures stay raw until its packet map is established.
Phone setup
- Android: open the deployed HTTPS URL in Google Chrome or Microsoft Edge. Web Bluetooth is native; Beacio is not required. Allow Bluetooth / Nearby devices when Android or the browser asks.
- iPhone: open the HTTPS URL in Safari, install and enable the Beacio Safari extension, then reload the page. Use a normal Safari tab.
- Select the correct model before connecting. G2 Ultra uses verified FFF0/FFF1/FFF2 transport with raw FFF2 capture; G2 keeps its independently observed shared map; old G2 Master FF55 data is never mixed in.
- Press Scan and select the scooter. The lab now shows nearby BLE devices for every model, then verifies that the selected device actually exposes FFF0. This avoids Chrome hiding scooters that expose FFF0 in GATT but do not advertise it.
- If Android Chrome says Bluetooth is unavailable, turn Bluetooth on and check Chrome's Nearby devices permission. Do not open the site inside TikTok, Discord, Telegram or another app's embedded browser.
- Keep both wheels safely clear of the ground for throttle or speed tests.
FFF1 writes use one simple enable switch and every TX is logged. Existing G2/G4 presets are sent once with no automatic retry. In G2 Ultra mode those presets are disabled because its command payloads are not verified; the manual HEX sender exists only for captured/known payloads. The site never writes to the separate f000ffc0-0451-4000-b000-000000000000 service.