What is a Modbus register?

Modbus exposes four separate tables of coils, discrete inputs, input registers and holding registers. What each one is, how wide it is, and why a value can span two of them.

6 min read · Updated

A Modbus device does not expose variables, objects or tag names. It exposes four flat tables of numbered locations, and every read or write refers to a position in one of them. Everything else — names, units, data types — lives in the device's documentation, not in the protocol.

The four tables

TableWidthAccessFunction codes
Coil1 bitRead / writeFC01 read, FC05/FC15 write
Discrete input1 bitRead onlyFC02
Input register16 bitsRead onlyFC04
Holding register16 bitsRead / writeFC03 read, FC06/FC16 write

The tables are independent. Holding register 100 and input register 100 have nothing to do with one another, and a device may implement one table and not another. There is no way to ask a device which addresses exist: a read either answers or returns an exception.

A register is 16 bits, and that is rarely enough

A single register holds an unsigned 16-bit value: 0 to 65,535. Real measurements do not fit that. A device reporting energy in watt-hours, or a temperature with one decimal place and a sign, has to use more than one register or agree a scaling factor with you.

Two conventions cover most devices:

  • Scaling — the register holds 2305 and the manual says the unit is 0.1 V, so the value is 230.5 V. The protocol carries the integer; the meaning is in the documentation.
  • Multi-register values — a 32-bit float or integer occupies two consecutive registers, a 64-bit value four. The device decides which register holds the high half, and vendors disagree.
A 32-bit value read with the wrong word order does not fail. It returns a plausible-looking number that is wrong, which is why byte order is the single most common cause of a bad first reading.

Bits inside a register

Status words often pack several booleans into one holding register, one per bit. The protocol has no concept of this; you read the register as a 16-bit value and mask the bit you want. A tool that lets you address a bit within a register saves you doing that arithmetic in the application.

What this means when you integrate a device

  1. Find which table the value lives in — it decides the function code.
  2. Find the address, and check whether the manual is quoting a protocol address or a 4xxxx-style reference.
  3. Find the width and the data type: one register or two, signed or unsigned, integer or float.
  4. Find the word order for anything wider than one register.
  5. Find the scaling factor and the engineering unit.

Those five facts are what a tag definition is. Everything a gateway or SCADA system does with the value depends on getting them right.

Free tool

Modbus Scanner

Connect to a device and understand its register map.

What is a Modbus register? | Modbus Logic