Configuration, status and data are exposed over four vendor GATT services. The services are grouped by function and shared across devices, so a characteristic means the same thing on every device that implements it.
Devices differ by which services they expose, not by having private numbering. A UWB device carries the UWB RTLS service; a BLE-only device does not, but still carries the same network, status and RTLS-configuration services as everything else.
Each service has its own 128-bit base. The 16-bit value at bytes 12–13 selects the characteristic within that service:
| Service | Base UUID |
|---|---|
UWB RTLS (0x51xx) | 63 D4 03 AF 51 78 23 14 1E EF 10 12 xx xx 00 00 |
Network configuration (0x81xx) | 23 D1 13 EF 5F 78 23 15 DE EF 12 12 xx xx 00 00 |
Device status (0x82xx) | FB 34 9B 5F 83 70 01 80 00 10 00 00 xx xx 00 00 |
RTLS configuration (0x83xx) | 17 56 13 E7 59 58 A3 05 DE EF 12 12 xx xx 00 00 |
Multi-byte values are little-endian throughout.
0x51xxPresent on every device with a UWB radio: Wristband Pro, the Fieldbus and Vehicle Anchor family, Locator Lite and Locator Lite XT.
| UUID | Characteristic | Access | Type |
|---|---|---|---|
0x5101 | Serial number | R | string, 16 B |
0x5102 | BLE MAC | R | 6 B |
0x5103 | Battery level | R | uint8, per cent |
0x5104 | Firmware version | R | string |
0x5105 | Device name | RW | string, 20 B |
On the anchor family, BLE MAC and firmware version are read from the device status service (0x8204/0x8207) rather than0x5102/0x5104. A client supporting both should fall back to the status service when these are absent.
| UUID | Characteristic | Type | Values |
|---|---|---|---|
0x5106 | UWB RTLS method | uint8 | 1 = TWR, 2 = TDoA |
0x5107 | Adaptive transmit | uint8 | accelerometer-driven: 0 off, 1 on |
0x5108 | Active blink rate | uint16 | 50–60 000 ms |
0x5109 | Inactive blink rate | uint16 | 50–60 000 ms; 0 = no transmissions while inactive |
0x510A | UWB channel | uint8 | channel number |
0x510B | UWB data rate | uint8 | 1 = LowDR, 2 = MidDR, 3 = HighDR |
0x510C | UWB preamble | uint8 | 1 = 64 … 6 = 2048, 7 = 4096 |
0x510D | UWB PRF | uint8 | 1 = 16 MHz, 2 = 64 MHz |
0x510E | UWB PAN ID | uint16 | network id |
0x510F | Enable TWR search | uint8 | when disabled, a tag stops searching after reaching the anchor limit |
0x5110 | Max anchors for TWR | uint8 | 3–255 |
0x5111 | Range data | R, 8 B | distance (2 B) + tag MAC (6 B) — this anchor |
0x5112 | Range data, secondary | R, 8 B | same shape, from a chained anchor |
Radio settings persist to flash immediately but take effect after restart. Defaults are on the fleet UWB PHY.
| UUID | Characteristic | Values |
|---|---|---|
0x5113–0x5115 | WiFi SSID, WiFi password, server address | strings — password is write-only |
0x5116 | Boarding mode | uint8 |
0x5117, 0x5118 | MAC filter 1, MAC filter 2 | 6 B each |
0x5119 | Anchor UART role | 0 = RX / master (aggregates), 1 = TX / slave |
0x511A | Tag MAC command | 7 B — 6 B MAC + 1 B command |
0x511B | Operating mode | 0 = CAS-PDS, 1 = UWB RTLS |
0x511C | Node role | 0 = anchor, 1 = tag — takes effect after restart |
0x511D | Connectivity mode | 0 = WiFi, 1 = RS-485, 2 = CAN |
0x511E | CAN controller variant | 0 = classic CAN 2.0B, 1 = CAN-FD |
0x511F | CAN bit rate | 0 = 1 Mbps, 1 = 500 k, 2 = 250 k, 3 = 125 k, 4 = 50 k |
0x5120 | Keep-alive period | uint16 seconds; 0 disables |
Each mirrors a runtime parameter, so the same setting is reachable over GATT, CAN and MQTT:
| UUID | Characteristic | Parameter | Values |
|---|---|---|---|
0x5121 | TDMA enable | 0x71 | 0 off, 1 on |
0x5122 | Ranging technology | 0x7A | 0 = UWB, 1 = UWB+BLE, 2 = BLE only |
0x5123 | Sensor telemetry enable | 0x77 | 0 off, 1 on |
0x5124 | Sensor mode | 0x78 | bit0 IMU raw, bit1 baro raw; else aggregated |
0x5125 | Sensor carrier | 0x7C | 0 = UWB frames, 1 = BLE ext advertising |
0x5126 | BLE ranging mode | 0x79 | 0 = RTT, 1 = MCPD |
0x5127 | TDMA sync master | 0x72 | exactly one device may set this |
0x5128 | Superframe period | 0x73 | uint32, microseconds |
0x5129 | Slot count | 0x74 | uint8 |
0x512A | CAP slots | 0x75 | uint8 — trailing contention-access slots |
0x512B | Sensor slots | 0x76 | uint8; 0 disables scheduled telemetry |
0x512C | BLE DM slots | 0x7B | uint8 |
0x512D | Node mode | 0x7D | 0 = RTLS anchor, 1 = RTLS tag, 2 = CAS-PDS anchor, 3 = CAS-PDS tag |
| UUID | Characteristic | Parameter | Values |
|---|---|---|---|
0x512E | GNSS enable | 0x7E | 0 off, 1 on |
0x512F | GNSS update rate | 0x7F | 0 = 2 s, 1 = 10 s, 2 = 30 s, 3 = 60 s |
0x5132 | GNSS mode | 0x80 | 0 = live, 1 = buffer & sync |
0x5133 | BLE advertising PHY | 0x81 | 0 = 1M, 1 = Coded |
0x5134 | BLE TX power | 0x82 | int8, dBm |
0x5135 | Site mode | 0x83 | 0 = auto, 1 = force indoor, 2 = force outdoor |
| UUID | Characteristic |
|---|---|
0x5136–0x513B | Scan period, WiFi sync, sync-on-beacon, hardware, beacon major, beacon minor |
These are reserved fleet-wide even though only Locator Lite XT implements them, so no other device reuses the UUIDs for a different meaning.
| UUID | Characteristic | Access |
|---|---|---|
0x5130 | Sync request — JSON command, ≤ 64 B | W |
0x5131 | Sync response — JSON or Protobuf, ≤ 512 B | R, read-authorized |
0x5164 | Device control — restart, power off, reset configuration | W |
0x5131 must be read-authorized: the read event is what confirms delivery and releases the drained records. Locator Lite XT additionally exposes it via notify.
0x81xxPresent on the anchor family and the Smart Lamp Locator.
| UUID | Characteristic |
|---|---|
0x8101 | WiFi network name |
0x8102 | WiFi password — write-only |
0x8103 | RADIUS name |
0x8104 | NTP server address |
0x8105 | Server address |
0x8106 | Server port |
0x8107 | Locator ID — the device identity used in MQTT topics and payloads |
0x8108 | MQTT topic prefix |
A credential is never readable over an unauthenticated connection: the WiFi password characteristic is write-only, and a group read reports only whether one is set.
0x82xxRead-only status. Present on the anchor family and the Smart Lamp Locator.
| UUID | Characteristic |
|---|---|
0x8201 | WiFi module status |
0x8202 | WiFi connection status |
0x8203 | Server connection status |
0x8204 | BLE MAC |
0x8205 | WiFi MAC |
0x8206 | IP address |
0x8207 | Firmware version |
0x8208 | Uplink module firmware version |
0x8209 | UWB module status |
0x83xxBLE RTLS tuning, proximity alerting and sensor options. Present on the anchor family and the Smart Lamp Locator — this is the service that configures Offline-online RMA behaviour.
| UUID | Characteristic |
|---|---|
0x8301 | Height |
0x8302, 0x8303 | Calibrated TX power — beacon, locator |
0x830A, 0x830B | RTLS minimum / maximum distance |
0x830C | RTLS second-minimum distance |
0x830F | Calibrated TX power, extended |
0x8310 | Filter type |
0x8311 | Beacons required for filtering |
0x8312 | Attenuation coefficient |
0x8313 | Scan interval and window |
| UUID | Characteristic |
|---|---|
0x8304 | Proximity group |
0x8305 | Proximity beacon ID |
0x8306 | Proximity distance |
0x830D | Broadcast all peer-to-peer |
| UUID | Characteristic |
|---|---|
0x8307 | RFID serial — read in the battery compartment |
0x8308 | Sensor option — fitted gas sensors, set at manufacture |
0x8309 | Time to online in ECO mode |
0x830E | Sleep duration, minutes |
0x8314, 0x8315 | Blink interval, blink enable |
0x8316 | Telemetry position reporting enable |
0x8317, 0x8318 | Modbus data TX / RX — external gas sensors |
0x83FE, 0x83FF | Password — new, old |
Sensor option values are listed on the Smart Lamp Locator page. On that device these characteristics are additionally reachable remotely over MQTT.
Locator Pro exposes an equivalent parameter set under a device-specific base UUID, and its characteristic offsets diverge from the map above. A client must discover this device's service rather than assume the layout of the four services.
Alignment across the line is by runtime parameter ID and MQTT payload key rather than by handle, so a setting carries the same meaning on Locator Pro even where the UUID differs.
Runtime parameters share one ID space reachable over GATT, the CAN daisy chain and MQTT. The same ID means the same thing on every transport. The space is append-only — IDs are never renumbered.
| ID | Meaning |
|---|---|
0x71 | TDMA enable |
0x72–0x76 | TDMA schedule — master, superframe, slot count, CAP slots, sensor slots |
0x77–0x79 | Sensor enable, sensor mode, BLE ranging mode |
0x7A, 0x7B | Ranging technology, BLE DM slots |
0x7C | Sensor carrier — 0 UWB, 1 BLE advertising |
0x7D | Node mode — combined operating mode and role |
0x7E, 0x7F | GNSS enable, GNSS update rate |
0x80–0x82 | GNSS mode, BLE advertising PHY, BLE TX power |
0x83 | Site mode |
0x84 | Battery present — configured, not detected |
IDs 0x72–0x76, 0x7B and 0x7D are master-authoritative TDMA schedule fields — a tag adopts them from the sync beacon and does not accept writes.
The TDMA and sensor runtime parameters live in RAM and revert to their defaults on reboot, so a commissioning value cannot strand a remote device. The full CAN-side table is on the CAN-FD page.