KuKirin BLE protocol lab

G2 / G2 Ultra / G4 Read + Write Lab

Disconnected

Recorder + decoder + controlled write laboratory

Read every mapped field and test exact FFF1 commands with readback verification.

The site subscribes to FFF2, decodes mapped G2/G4 fields, records G2 Ultra packets raw until they are mapped, and exposes direct mode, zero-start, speed/power-curve, speed-config and factory-reset commands through FFF1 behind one switch. Lights remain readable; the uploaded APK proved the old F04C02xx “light” guess was actually zero-start.

Vehicle under test G4 decoding is enabled. The model is stamped into every exported row.
ServiceFFF0
NotifyFFF2
WriteFFF1not connected
DecoderG4 FFF2 shared v3
Packets0
RecordingStopped
Capture time00:00
Tests passed0 / 17
DeviceNone
0.0km/hBLE raw —
Peak0.0 km/h
Integrated trip0.000 km
Distance tick delta0.0 km

G4 display calibration v2: BLE ÷16 remains the raw wheel-speed source. The main gauge is unchanged through 15 km/h, then applies the latest tester-derived correction: roughly 2 km/h correction near 20, ramping toward ~6 km/h at the top of the unloaded run. Raw BLE speed is always shown and exported.

High confidence

Mapped telemetry

validated map
Ride mode——
Battery—%2A19: —
Motor temperature— °CFrame B 0..1 LE
Current / load candidate— AFrame B 8..9 LE ÷100
Lights—Frame A offset 17 bit 0
Drive request—Frame A offset 4 bit 1
Brake input—Frame A offset 4 bit 3
Brake output mirror—Frame A offset 14 bit 3

Mode profile

Controller limits

Current/torque profile candidate—Observed 25 / 30 / 40
Speed profile raw—Observed 20 / 40 / 99
Nominal voltage—Observed 60 V

Still under investigation

Unknown and lower-confidence fields

do not rename yet
Dynamic byte A8—range —
Possible ambient/controller temp A9—range —
Static flags A11—
Possible fault word A12..13—
Output flags A14—
Constants A15 / A16—

Packet health

Frame families

128-byte startup fills0
20-byte Frame A0
11-byte Frame B0
Unknown lengths0
Last FFF2 packetWaiting…

Guided physical validation

Start a test, perform the action, and let the decoder judge the evidence.

Guided validation starts with the G4 profile map.

Active instruction

No test selected

Choose Start on a test card. The site will add markers automatically.

Direct FFF1 controls

Mode, zero-start, speed/power curves, speed config, and recovery.

Direct F0 command frames. One write-enable switch; no phrase, timer, checklist, or passive-frame replay.

Correction from reset.apk: F0 4C 02 00/01 belongs to ControlPresenter.zeroStart. The old light-write guess is removed; light state is still read from FFF2.

FFF1Unavailable
WritesOff
Last writeNone

Control switch

Enable direct FFF1 writes

Once enabled, the controls are writable immediately. Commands are sent once with no automatic retry. The red reset control is a FACTORY RESET.

Manual transport lab

Send raw FFF1 HEX once

Manual transport test: enter raw hex for FFF1. It is sent exactly once and logged.

Explicit BLE reads

Read every available characteristic now

Manufacturer—
Model—
Serial—
Hardware revision—
PnP ID—

Write evidence

Command and readback results

TimeModelCommandTXExpected readbackResult
No writes sent.

Automatic CSV logging

Waiting for connection

Logging begins when FFF2 notifications start and also records explicit reads and FFF1 writes.

Manual markers

Tap before the action

Live stream

BLE traffic: RX, reads and TX

#TimeModelDirectionSourceFamily / operationHex / marker
No capture yet.

Offline validation

Load an exported CSV on any phone or computer.

The file is processed locally in the browser. Nothing is uploaded.

Loaded file

No CSV loaded

Choose a G2, G2 Ultra or G4 CSV. G2 Ultra captures stay raw until its packet map is established.

Phone setup

  1. Android: open the deployed HTTPS URL in Google Chrome or Microsoft Edge. Web Bluetooth is native; Beacio is not required. Allow Bluetooth / Nearby devices when Android or the browser asks.
  2. iPhone: open the HTTPS URL in Safari, install and enable the Beacio Safari extension, then reload the page. Use a normal Safari tab.
  3. Select the correct model before connecting. G2 Ultra uses verified FFF0/FFF1/FFF2 transport with raw FFF2 capture; G2 keeps its independently observed shared map; old G2 Master FF55 data is never mixed in.
  4. Press Scan and select the scooter. The lab now shows nearby BLE devices for every model, then verifies that the selected device actually exposes FFF0. This avoids Chrome hiding scooters that expose FFF0 in GATT but do not advertise it.
  5. If Android Chrome says Bluetooth is unavailable, turn Bluetooth on and check Chrome's Nearby devices permission. Do not open the site inside TikTok, Discord, Telegram or another app's embedded browser.
  6. Keep both wheels safely clear of the ground for throttle or speed tests.
Write boundary

FFF1 writes use one simple enable switch and every TX is logged. Existing G2/G4 presets are sent once with no automatic retry. In G2 Ultra mode those presets are disabled because its command payloads are not verified; the manual HEX sender exists only for captured/known payloads. The site never writes to the separate f000ffc0-0451-4000-b000-000000000000 service.