Modbus function codes explained: FC 01, 02, 03, 04, 05, 06, 15, 16, plus 08, 17, 22, 23 and 43/14
The function code tells the Modbus server/slave what operation to perform. For most commissioning work, FC 01, 02, 03, 04, 05, 06, 15 and 16 cover the core read/write operations. FC 08, 17, 22, 23 and 43 add diagnostics, identification and atomic register operations.
Quick answer: A Modbus function code is a one-byte command that tells the slave/server what to do. FC 01 and 02 read coils and discrete inputs, FC 03 and 04 read holding and input registers, FC 05 and 06 write a single coil or register, and FC 15 and 16 write multiple coils or registers. Less common codes include FC 08 (diagnostics), FC 17 (report slave ID), FC 22 (mask write), FC 23 (read/write multiple registers) and FC 43/14 (read device identification).
What are the common Modbus function codes?
| FC | Name | Data | Typical use |
|---|---|---|---|
| 01 | Read Coils | 1-bit R/W | Digital outputs / commands |
| 02 | Read Discrete Inputs | 1-bit read-only | Digital status |
| 03 | Read Holding Registers | 16-bit R/W | Setpoints, measurements, configuration |
| 04 | Read Input Registers | 16-bit read-only | Measurements |
| 05 | Write Single Coil | 1 bit | One digital command |
| 06 | Write Single Register | 16 bit | One setpoint/register |
| 15 | Write Multiple Coils | Multiple bits | Batch digital writes |
| 16 | Write Multiple Registers | Multiple 16-bit | 32-bit values / blocks |
What do FC 08, 17, 22, 23 and 43 do?
Many devices also implement some of these optional function codes. Support varies by device, so a device that does not implement one answers with exception 01 Illegal Function.
| FC | Name | What it does | ModbusBB 2.0 |
|---|---|---|---|
| 08 | Diagnostics | Serial-line diagnostics. Sub-function 0 (Return Query Data) echoes the request data back, which makes it a quick end-to-end link test. Counter sub-functions return one 16-bit value. | Device Tools > Diagnostics; CLI diag |
| 17 (0x11) | Report Server/Slave ID | Returns a device-specific server ID, a run indicator (0xFF = ON) and optional additional data. | Device Tools > Report Slave ID; CLI slaveid |
| 22 (0x16) | Mask Write Register | Changes individual bits of one holding register in a single request: result = (current AND and-mask) OR (or-mask AND NOT and-mask). | Device Tools > Mask Write (with bit preview); CLI maskwrite |
| 23 (0x17) | Read/Write Multiple Registers | Writes a block of registers and reads a block in one transaction. The write is performed before the read. | Device Tools > Read/Write Multiple; CLI rw |
| 43 / 14 (0x2B / 0x0E) | Read Device Identification | Returns identification objects: Basic (vendor, product code, revision), Regular (adds vendor URL, product name, model name, application name), Extended (private objects) or one Individual object. | Device Tools > Device Identification; CLI devid |
For any other function code, ModbusBB’s Raw Request tool (Device Tools, or the CLI raw command) sends function code 1-127 with your own data bytes and shows the request and response frames, including exception replies. See Device Tools and the CLI commands.
What is the difference between FC 03 and FC 04?
FC 03 reads holding registers; FC 04 reads input registers. A manufacturer may store measurements in either area. If FC 03 returns Illegal Function or Illegal Data Address, check whether the manual specifies input registers and try FC 04 instead.
The address number alone does not identify the area inside the Modbus frame. The function code does.
How do you write a 32-bit value over Modbus?
A Float32, Int32 or UInt32 value occupies two 16-bit registers. Depending on the device, writing the value may require FC 16 so both registers are updated in one transaction. The byte/word order must also match the device. See the Float32 byte-order guide.
What happens when a device rejects a request?
When a slave cannot execute a request, it returns an exception response rather than normal data. Common reasons include an unsupported function, an invalid address or a value outside the allowed range. The Modbus error-code guide explains the common exception codes and fixes.
Safe commissioning practice
When possible, test write logic first against a simulator, then move to the real device with controlled values and clear rollback steps. The ModbusBB simulator answers FC 01-06, 08, 15, 16 and 23 and returns 01 Illegal Function for other codes. In the GUI, rows read with FC 02 or FC 04 are read-only, so a value in a read-only area cannot be written by mistake. ModbusBB Device Tools can also ask for confirmation before any request that changes data.
Modbus Organization reference
For protocol-level definitions, use the official MODBUS Application Protocol Specification V1.1b3.
Frequently asked questions
What is the difference between FC 03 and FC 04?
FC 03 reads holding registers, which are read/write and often hold setpoints and configuration. FC 04 reads input registers, which are read-only measurements. Manufacturers put measured values in either area, so check the register map; if FC 03 returns Illegal Function or Illegal Data Address, try FC 04.
Which function code writes a 32-bit or Float32 value?
Use FC 16 (Write Multiple Registers) so both 16-bit registers are written in one transaction; FC 06 writes only one register. The word and byte order must match what the device expects (ABCD, CDAB, BADC or DCBA).
Which Modbus function codes does ModbusBB support?
ModbusBB 2.0 supports FC 01, 02, 03, 04, 05, 06, 15 and 16 for polling and writing, plus FC 08 (diagnostics), FC 17 (report slave ID), FC 22 (mask write), FC 23 (read/write multiple) and FC 43/14 (device identification) in Device Tools and the CLI. A raw request tool sends any function code from 1 to 127. It works over Modbus TCP, UDP, RTU, ASCII and RTU-over-TCP.
How do I test whether a device supports FC 43 device identification?
Send a Read Device Identification request (FC 43, MEI type 14) with category Basic. In ModbusBB use Tools > Device Tools > Device Identification, or run ModbusBB.CLI devid --tcp <ip> --unit <id>. A device without support answers with exception 01 Illegal Function.
Use ModbusBB while you troubleshoot
Connect, scan, read/write, inspect raw TX/RX traffic, trend data or simulate a device from the same Windows application.