Wiki

Technical reference for system integrators and engineers.

BLE GATT

Configuration, status and data are exposed over four vendor GATT services. The services are grouped by function and shared across devices, so a characteristic means the same thing on every device that implements it.

The four services

Devices differ by which services they expose, not by having private numbering. A UWB device carries the UWB RTLS service; a BLE-only device does not, but still carries the same network, status and RTLS-configuration services as everything else.

0x51xx UWB RTLS radio · ranging · TDMA · sync 0x81xx Network configuration WiFi · server · NTP 0x82xx Device status MAC · IP · versions 0x83xx RTLS configuration BLE tuning · proximity Which devices expose which Fieldbus / Vehicle Anchor, Locator Lite 0x51xx + 0x81xx + 0x82xx + 0x83xx Wristband Pro, Locator Lite XT 0x51xx Smart Lamp Locator — BLE only, no UWB radio 0x81xx + 0x82xx + 0x83xx
Locator Pro is the exception — it exposes an equivalent parameter set under a device-specific base UUID.

Base UUIDs

Each service has its own 128-bit base. The 16-bit value at bytes 12–13 selects the characteristic within that service:

ServiceBase UUID
UWB RTLS (0x51xx)63 D4 03 AF 51 78 23 14 1E EF 10 12 xx xx 00 00
Network configuration (0x81xx)23 D1 13 EF 5F 78 23 15 DE EF 12 12 xx xx 00 00
Device status (0x82xx)FB 34 9B 5F 83 70 01 80 00 10 00 00 xx xx 00 00
RTLS configuration (0x83xx)17 56 13 E7 59 58 A3 05 DE EF 12 12 xx xx 00 00

Multi-byte values are little-endian throughout.

UWB RTLS service — 0x51xx

Present on every device with a UWB radio: Wristband Pro, the Fieldbus and Vehicle Anchor family, Locator Lite and Locator Lite XT.

Identity

UUIDCharacteristicAccessType
0x5101Serial numberRstring, 16 B
0x5102BLE MACR6 B
0x5103Battery levelRuint8, per cent
0x5104Firmware versionRstring
0x5105Device nameRWstring, 20 B
On the anchor family, BLE MAC and firmware version are read from the device status service (0x8204 / 0x8207) rather than 0x5102 / 0x5104. A client supporting both should fall back to the status service when these are absent.

UWB radio and ranging

UUIDCharacteristicTypeValues
0x5106UWB RTLS methoduint81 = TWR, 2 = TDoA
0x5107Adaptive transmituint8accelerometer-driven: 0 off, 1 on
0x5108Active blink rateuint1650–60 000 ms
0x5109Inactive blink rateuint1650–60 000 ms; 0 = no transmissions while inactive
0x510AUWB channeluint8channel number
0x510BUWB data rateuint81 = LowDR, 2 = MidDR, 3 = HighDR
0x510CUWB preambleuint81 = 64 … 6 = 2048, 7 = 4096
0x510DUWB PRFuint81 = 16 MHz, 2 = 64 MHz
0x510EUWB PAN IDuint16network id
0x510FEnable TWR searchuint8when disabled, a tag stops searching after reaching the anchor limit
0x5110Max anchors for TWRuint83–255
0x5111Range dataR, 8 Bdistance (2 B) + tag MAC (6 B) — this anchor
0x5112Range data, secondaryR, 8 Bsame shape, from a chained anchor

Radio settings persist to flash immediately but take effect after restart. Defaults are on the fleet UWB PHY.

Role, transport and chain

UUIDCharacteristicValues
0x51130x5115WiFi SSID, WiFi password, server addressstrings — password is write-only
0x5116Boarding modeuint8
0x5117, 0x5118MAC filter 1, MAC filter 26 B each
0x5119Anchor UART role0 = RX / master (aggregates), 1 = TX / slave
0x511ATag MAC command7 B — 6 B MAC + 1 B command
0x511BOperating mode0 = CAS-PDS, 1 = UWB RTLS
0x511CNode role0 = anchor, 1 = tag — takes effect after restart
0x511DConnectivity mode0 = WiFi, 1 = RS-485, 2 = CAN
0x511ECAN controller variant0 = classic CAN 2.0B, 1 = CAN-FD
0x511FCAN bit rate0 = 1 Mbps, 1 = 500 k, 2 = 250 k, 3 = 125 k, 4 = 50 k
0x5120Keep-alive perioduint16 seconds; 0 disables

TDMA and sensors

Each mirrors a runtime parameter, so the same setting is reachable over GATT, CAN and MQTT:

UUIDCharacteristicParameterValues
0x5121TDMA enable0x710 off, 1 on
0x5122Ranging technology0x7A0 = UWB, 1 = UWB+BLE, 2 = BLE only
0x5123Sensor telemetry enable0x770 off, 1 on
0x5124Sensor mode0x78bit0 IMU raw, bit1 baro raw; else aggregated
0x5125Sensor carrier0x7C0 = UWB frames, 1 = BLE ext advertising
0x5126BLE ranging mode0x790 = RTT, 1 = MCPD
0x5127TDMA sync master0x72exactly one device may set this
0x5128Superframe period0x73uint32, microseconds
0x5129Slot count0x74uint8
0x512ACAP slots0x75uint8 — trailing contention-access slots
0x512BSensor slots0x76uint8; 0 disables scheduled telemetry
0x512CBLE DM slots0x7Buint8
0x512DNode mode0x7D0 = RTLS anchor, 1 = RTLS tag, 2 = CAS-PDS anchor, 3 = CAS-PDS tag

GNSS and radio environment

UUIDCharacteristicParameterValues
0x512EGNSS enable0x7E0 off, 1 on
0x512FGNSS update rate0x7F0 = 2 s, 1 = 10 s, 2 = 30 s, 3 = 60 s
0x5132GNSS mode0x800 = live, 1 = buffer & sync
0x5133BLE advertising PHY0x810 = 1M, 1 = Coded
0x5134BLE TX power0x82int8, dBm
0x5135Site mode0x830 = auto, 1 = force indoor, 2 = force outdoor

Reverse RTLS — Locator Lite XT

UUIDCharacteristic
0x51360x513BScan period, WiFi sync, sync-on-beacon, hardware, beacon major, beacon minor

These are reserved fleet-wide even though only Locator Lite XT implements them, so no other device reuses the UUIDs for a different meaning.

Data sync and control

UUIDCharacteristicAccess
0x5130Sync request — JSON command, ≤ 64 BW
0x5131Sync response — JSON or Protobuf, ≤ 512 BR, read-authorized
0x5164Device control — restart, power off, reset configurationW

0x5131 must be read-authorized: the read event is what confirms delivery and releases the drained records. Locator Lite XT additionally exposes it via notify.

Network configuration service — 0x81xx

Present on the anchor family and the Smart Lamp Locator.

UUIDCharacteristic
0x8101WiFi network name
0x8102WiFi password — write-only
0x8103RADIUS name
0x8104NTP server address
0x8105Server address
0x8106Server port
0x8107Locator ID — the device identity used in MQTT topics and payloads
0x8108MQTT topic prefix
A credential is never readable over an unauthenticated connection: the WiFi password characteristic is write-only, and a group read reports only whether one is set.

Device status service — 0x82xx

Read-only status. Present on the anchor family and the Smart Lamp Locator.

UUIDCharacteristic
0x8201WiFi module status
0x8202WiFi connection status
0x8203Server connection status
0x8204BLE MAC
0x8205WiFi MAC
0x8206IP address
0x8207Firmware version
0x8208Uplink module firmware version
0x8209UWB module status

RTLS configuration service — 0x83xx

BLE RTLS tuning, proximity alerting and sensor options. Present on the anchor family and the Smart Lamp Locator — this is the service that configures Offline-online RMA behaviour.

Positioning and filtering

UUIDCharacteristic
0x8301Height
0x8302, 0x8303Calibrated TX power — beacon, locator
0x830A, 0x830BRTLS minimum / maximum distance
0x830CRTLS second-minimum distance
0x830FCalibrated TX power, extended
0x8310Filter type
0x8311Beacons required for filtering
0x8312Attenuation coefficient
0x8313Scan interval and window

Proximity alerting

UUIDCharacteristic
0x8304Proximity group
0x8305Proximity beacon ID
0x8306Proximity distance
0x830DBroadcast all peer-to-peer

Device options and power

UUIDCharacteristic
0x8307RFID serial — read in the battery compartment
0x8308Sensor option — fitted gas sensors, set at manufacture
0x8309Time to online in ECO mode
0x830ESleep duration, minutes
0x8314, 0x8315Blink interval, blink enable
0x8316Telemetry position reporting enable
0x8317, 0x8318Modbus data TX / RX — external gas sensors
0x83FE, 0x83FFPassword — new, old

Sensor option values are listed on the Smart Lamp Locator page. On that device these characteristics are additionally reachable remotely over MQTT.

Locator Pro

Locator Pro exposes an equivalent parameter set under a device-specific base UUID, and its characteristic offsets diverge from the map above. A client must discover this device's service rather than assume the layout of the four services.

Alignment across the line is by runtime parameter ID and MQTT payload key rather than by handle, so a setting carries the same meaning on Locator Pro even where the UUID differs.

Runtime parameter IDs

Runtime parameters share one ID space reachable over GATT, the CAN daisy chain and MQTT. The same ID means the same thing on every transport. The space is append-only — IDs are never renumbered.

IDMeaning
0x71TDMA enable
0x720x76TDMA schedule — master, superframe, slot count, CAP slots, sensor slots
0x770x79Sensor enable, sensor mode, BLE ranging mode
0x7A, 0x7BRanging technology, BLE DM slots
0x7CSensor carrier — 0 UWB, 1 BLE advertising
0x7DNode mode — combined operating mode and role
0x7E, 0x7FGNSS enable, GNSS update rate
0x800x82GNSS mode, BLE advertising PHY, BLE TX power
0x83Site mode
0x84Battery present — configured, not detected

IDs 0x720x76, 0x7B and 0x7D are master-authoritative TDMA schedule fields — a tag adopts them from the sync beacon and does not accept writes.

The TDMA and sensor runtime parameters live in RAM and revert to their defaults on reboot, so a commissioning value cannot strand a remote device. The full CAN-side table is on the CAN-FD page.