energieresearch
aegsolarcubemodbusrs485hyxihome-assistantthuisbatterijstekkerbatterij

AEG SolarCube Pro Modbus registers (AS-BBL08 / HYXi HALO): what works and what only stores

The AEG SolarCube Pro (AS-BBL08) has an RS485 port that speaks Modbus, locally and without an account, but we found no register document that matches this unit. This is the register map we built ourselves and checked register by register against the unit: how to connect, which registers work, how to control charge and discharge, which registers store a value and do nothing, and which block you never write. The whole map is also available as a CSV download.

JJooshua
··23 min read
In this article14
  1. Connecting to the RS485 port of the AEG SolarCube
  2. Holding and input are two separate spaces
  3. Identity: model string, firmware and rated power
  4. Live values: state of charge, power and cells
  5. Work mode, on and off
  6. Controlling discharge: the schedule table from 4178
  7. Controlling charge: forced charge with 4132, 4140 and 4113
  8. Registers that store a value and do nothing
  9. Holding 140 to 179: never write
  10. Behaviour a script has to handle
  11. The register map as CSV
  12. What is still open
  13. Frequently asked questions
  14. Sources

TL;DR

The AEG SolarCube Pro (AS-BBL08) has an RS485 port that speaks Modbus, locally and without an account, but we found no register document that matches this unit. This is the register map we built ourselves and checked register by register against the unit: how to connect, which registers work, how to control charge and discharge, which registers store a value and do nothing, and which block you never write. The whole map is also available as a CSV download.

The AEG SolarCube Pro, model number AS-BBL08, has an RS485 port on the back that speaks Modbus. We found no register document from AEG or HYXi that matches this unit. HYXi builds it, and it is an AEG-badged HYXi HALO: the register layout is shared, the meaning of the registers is not. own measurementModbus reads over RS485, set against HYXi's register document · 12 September 2026 This page lists the Modbus registers we mapped ourselves, each one checked against the app, the metering socket or the behaviour of the unit. What the battery itself delivers is in the AEG SolarCube Pro review. This page is only about reading and control.

The whole map is also in one file: aeg-solarcube-as-bbl08-modbus-registers.csv, 46 rows. What the columns mean is at the bottom, with the download.

ℹ️Info

This map holds for one unit, with firmware 331 / 259 / 286 / 259 and control software V01.03.01.1E. We have not seen another version. After an update an address can move or a meaning can change. So check every register against your own unit before you control it. own measurementModbus reads over RS485, each register checked against app, meter or behaviour · 30 September 2026

Connecting to the RS485 port of the AEG SolarCube

The port is D, on the main unit. The manual describes it as a standard network-cable port for a third-party energy manager to control your system. manufacturerAS-BBL08 user manual V1.0-26, page 9, port legend The specification table of the datasheet does not list it. It says "WiFi / Bluetooth / CAN", and footnote 5 makes CAN the line to the battery module. manufacturerdatasheet V2.0, communication row and footnote 5 · 12 September 2026

SettingValueSource
PortD, RS485, an RJ45 socket on the main unitmanufacturer, manual p. 9
Wirespin 7 = A, pin 8 = B; in T568B that is white-brown and brownown measurement, 2026-09-12
Serial settings115200 baud, 8N1own measurement, 2026-09-12
Unit id1; it answers on every unit id as itself, the packs have no address of their ownown measurement, 2026-09-12
Function codes3 (read holding), 4 (read input), 16 (write)own measurement, 2026-09-12
PathRS485 to Modbus TCP through a bridge; no cloud and no accountown measurement, 2026-09-25

Our bridge was a USR-W610 in Modbus TCP to RTU translation mode. In that mode, use plain Modbus TCP framing (MBAP); RTU over TCP timed out for us. At 9600 baud the bus stays dead. If two programs share the same bridge, check the transaction id on every reply. Without that check one program receives the other's answers, and on 25 September that gave us a scan in which whole blocks sat 150 to 200 registers out of place. own measurementModbus TCP through a USR-W610 to RS485

Other function codes time out: 43/14 (device identification), 20 (file record), 17 and 8. Coils and discrete inputs (function codes 1 and 2) do not exist anywhere between 0 and 9999. So there is no way to update the firmware over Modbus. own measurementModbus scan over RS485

Control over this port needs no internet. It is also the only local path: the communication module has every port closed on the home network and talks only to the cloud. own measurementModbus TCP through an RS485 bridge, and a port scan of the communication module · 25 September 2026

Holding and input are two separate spaces

On this unit, holding (function code 3) and input (function code 4) are different registers, also where the address is the same. Input 4048 and 4049 are the rated frequency and voltage; holding 4048 and 4049 is a dispatch pair that does nothing. HYXi's register document does not make that distinction. own measurementModbus reads and a write test · 12 September 2026

Above 9999 it gives well-formed replies with no content on function codes 3 and 4. A scanner that counts every reply without an exception as a hit finds about thirty false islands there. own measurementModbus scan over RS485, 10000 to 65535

Where HYXi uses a name of its own for a register, in its register document or in the firmware, that name is in the tables and in the CSV. Such a name is a lead, not proof. The HYXi document we found, Micro Storage RS485 MODBUS V1.0, does not hold for this unit, also where the addresses match. So do not use it to correct this map. If you build a driver, key it on the model string AS-BBL08-3K and never on "HALO". Then a HYXi-badged unit does not silently inherit the behaviour of this AEG. own measurementModbus reads, register by register next to HYXi's document · 12 September 2026

Identity: model string, firmware and rated power

RegisterSpaceWhat it doesSource
4002-4007inputmodel string, two characters per register with the bytes swapped: AS-BBL08-3Kown measurement, 2026-09-12
3100 / 3180inputinternal model name, also byte-swapped: HYX-MS3000Bown measurement
4026-4029inputfirmware versions, here 331 / 259 / 286 / 259; 4027 = 0x103 and 4028 = 0x11E match control software V01.03.01.1E in the appown measurement, 2026-09-12
4046inputrated power: 3000 Wown measurement, 2026-09-12
4048 / 4049inputrated frequency and voltage, times 0.01: 50.00 Hz and 230.0 Vown measurement, 2026-09-12
4978inputthe number of packs that report, 1 or 2own measurement, 2026-09-25
4981inputalways 1000. Not capacity. HYXi calls it soh; 100.0 % state of health fits, but it is not verifiedown measurement, 2026-09-27

Every text we read in the registers had the two bytes of each register swapped. Swap them back before you compare the string.

Live values: state of charge, power and cells

RegisterSpaceWhat it doesSource
3030 / 3130inputstate of charge of pack 1 and pack 2, in tenths of a percent. The reliable source: 491 read as 49.1 % against 49 % in the appown measurement, 2026-09-12
3033 / 3133inputstate of health of pack 1 and pack 2, in percentown measurement, 2026-09-12
3035 / 3135inputpower per pack, signed watts; together within 3 W of 4985own measurement, 2026-09-12
3034 / 3134inputa second power pair; together about 12 W above the measured DC power. Do not add it upown measurement, 2026-09-12
3039 / 3139inputhighest cell voltage of pack 1 and pack 2, in mVown measurement, 2026-09-12
3040 / 3140inputlowest cell voltage of pack 1 and pack 2, in mVown measurement, 2026-09-12
3045 / 3145inputwarmest cell, in tenths of a degreeown measurement, 2026-09-12
3046 / 3146inputcoldest cell, in tenths of a degreeown measurement, 2026-09-12
4985inputbattery DC power, 32-bit, low word first; positive is discharge, negative is chargeown measurement, 2026-09-12
4152inputAC power, mirrored at 4163; positive is export. Not usable near zeroown measurement, 2026-09-12
5021 / 5023inputmaximum discharge and charge power, 32-bit, low word first: the grid setting times 0.95, so 760 or 2850 Wown measurement, 800 W and 3000 W settings, 2026-09-12
4151inputgrid frequency, times 0.01: 4997 is 49.97 Hzown measurement
4161 / 4210inputgrid voltage, times 0.01: 23426 is 234.26 Vown measurement
4982inputnot the state of charge. It read 39 to 46 % while the packs were at 48 to 49 %, and it moves independently of chargingown measurement

Control on the lower of 3030 and 3130. 4982 looks like a state of charge and cost us most of a session before we saw that it is not one. own measurementModbus reads next to the app · 12 September 2026

5021 and 5023 report what the unit can do at that moment, not the setting in the app. Off the grid and just after reconnecting they fall away. A script that reads a ceiling from them before it starts then aborts for no reason or commands too little. Read them only once 4979 is at 4. own measurementModbus reads while disconnecting and reconnecting, 800 W grid setting · 12 September 2026 No register writes the grid setting itself, 800 or 3000 W. It lives only in the app. own measurementModbus reads and app, 800 W and 3000 W grid settings · 12 September 2026

Work mode, on and off

RegisterSpaceWhat it doesSource
4021holdingon and off: 1 = on, 3 = standby, 0 = while booting. A 2 is acknowledged and reads back as 3; there is no deeper offown measurement, 2026-09-30
4024holdingwork mode: 3 = Backup, 21 = Custom, 22 = Time of Use, 23 = thirdpartyEMS. 1 and 2 are the two self-consumption modes; which is which is not settled. It stores any value, so write nothing outside this listown measurement, 2026-09-12
4102inputthe mode the app shows, including a mode the firmware imposes. Not a mirror of 4024own measurement
4979inputconnection state: 4 = connected to the grid, 3 and 5 = retrying before connecting, 11 = briefly while reconfiguring, 7 = locked out on battery undervoltageown measurement, 2026-09-25
5000inputthe battery alarm word, mirrored at 3050. What each bit means is not establishedown measurement, 2026-09-25
4109 / 4110 / 4111inputprobably temperatures in the inverter, in tenths of a degree. The meaning is not confirmedown measurement

The thirdpartyEMS mode reports itself as such and accepts a power value by no path we tried. Custom, with the schedule table below, is the mode in which you set a discharge power over Modbus. own measurementModbus writes, mode by mode · 12 September 2026

Standby is not off. With 4021 at 3 it draws about 9.5 W, and with the power button off 9.3 W; Modbus keeps answering in both cases. Off the grid, that draw comes from the battery. own measurementmetering socket and Modbus reads, after the recovery · 30 September 2026 That is how our unit drained until the battery management locked it out. What the error code then means and how it came back is on the page about error code 170305110.

Controlling discharge: the schedule table from 4178

It has no power setpoint register. You control discharge through the schedule table the app itself uses in Custom mode. The proof that it is the same table: when the app held three time slots of 15, 30 and 45 W, exactly those values with exactly those boundaries sat in 4181 to 4200, in a change we had not written over the bus. own measurementModbus reads next to the app · 12 September 2026

4024 = 21                       work mode Custom
4178 = 1                        PeriodNum: 1 or higher, or the schedule reads as empty
4179 = 127                      days as a bitmask, 127 = every day
4180 = 1                        the number of slots
4181, 4182, 4183, 4184          slot 0: start, end, mode, power
  = 0, 1440, 21, <watts>        start and end in minutes of the day

Slot n starts at 4181 + 8n and takes eight registers. The first four are start, end, mode and power; what the other four do is not settled. The mode in the slot takes the same values as 4024. own measurementModbus writes, confirmed on 4985 · 1 October 2026

We never wrote 4178 at first. On our unit it sat at 0 after a full reset, the whole schedule read as empty and the unit delivered the 200 W default, so every slot write looked ignored. So always set it. own measurementModbus writes after a full reset · 1 October 2026

The power in a slot is an unsigned discharge power. A slot does not charge. If you write a negative number, it reads it as a large positive one and discharges at its maximum. own measurementModbus writes, confirmed on 4985, 800 W grid setting · 1 October 2026

An empty schedule is not zero. With no valid slot it discharges 200 W; the app itself warns about it. To make it stand still, set one all-day slot to 0 W: 4180 = 1 and slot 0 = [0, 1440, 21, 0]. own measurementModbus reads and the notice in the app · 16 September 2026

What you write into the slots over the bus is lost on a full reset. The schedule set in the app survives that reset. Give every script a restore on exit, and set the slot power to 0 there instead of commanding a previously captured power again. own measurementModbus reads before and after a full reset · 16 September 2026

Controlling charge: forced charge with 4132, 4140 and 4113

You cannot pick the charge power in the app, and not in a slot either. Over Modbus you can, with a forced charge:

  1. Set 4021 to 1. From standby a forced charge does nothing, and the grid has to be connected.
  2. Set 4132, the start state of charge, above the current state of charge. It then charges at the grid setting.
  3. Set 4140, the stop state of charge, to your target. The unit enforces that limit itself, also when the script that controls it stops halfway.
  4. Set 4113 to the limit you want.
own measurementModbus writes and metering socket · 1 October 2026

4113 limits the charge power only while a forced charge runs, and the relation is linear: about 19 W per step, from about 190 W up to the ceiling of the grid setting. During discharge 4113 does nothing. HYXi calls the register MaxChargeCurrent. Which unit the device reads into it is not settled, so work with what was measured.

≈ 19 W

charge power per step in register 4113, during a forced charge

Bron: own measurement, 800 W grid setting, 1 October 2026

4113Charge power, DCSource
10192 Wown measurement, 800 W setting, 2026-10-01
20382 Wown measurement, 800 W setting, 2026-10-01
30569 Wown measurement, 800 W setting, 2026-10-01
40752 Wown measurement, 800 W setting, 2026-10-01
50 and up760 W, the ceiling of the 800 W settingown measurement, 800 W setting, 2026-10-01

It worked on the unit itself and it is reversible: one write took it from discharging to charging. Values below 10 are not in our measurement, and on the 3000 W setting, between 760 and 2850 W, we did not measure 4113. own measurementour techbench, metering socket, Modbus writes to 4113 during a forced charge, 800 W grid setting · 1 October 2026

RegisterSpaceWhat it doesSource
4132holdingforced charge, start state of charge in percent (force_charge_start_soc)own measurement, 2026-09-12
4140holdingforced charge, stop state of charge in percent, enforced by the unit itself (force_charge_stop_soc)own measurement, 2026-09-12
4113holdingcharge limit during a forced charge, about 19 W per step (MaxChargeCurrent)own measurement, 800 W setting, 2026-10-01
4121holdinganti-starvation protection, 1 = on (anti_starvation). Charges from the grid, so off the grid it does nothingown measurement, 2026-09-27
4133holdingminimum state of charge for off-grid, in whole percent (off_grid_min_soc)own measurement, 2026-09-27
4134holdingminimum state of charge for self-consumption, in whole percent (self_use_soc)own measurement, 2026-09-27
4141holdingminimum state of charge for discharge, in whole percent (discharge_min_soc). Applies to discharge, not to what the unit uses itselfown measurement, 2026-09-27

None of these limits is a voltage limit. They are states of charge. own measurementModbus reads of the settings, holding 4121 to 4141 · 27 September 2026

Registers that store a value and do nothing

The unit does not check a write when it receives it, only when it executes it. A successful read-back proves storage, not obedience: 4148 accepted 65000. After every write, look at the DC power in 4985, and never only at the read-back straight after it. own measurementModbus writes and reads, register by register · 12 September 2026

RegisterSpaceWhat happensSource
3961holdingstores and reads back, controls nothing. It looked like a power register while a slot happened to hold the same powerown measurement, 2026-09-12
4118-4120holdingBatterySetPower and BatteryForceControlEnable in HYXi's naming. Accepts a value and keeps it; nothing in this firmware acts on it. Not the charge pathown measurement, 2026-10-01
4146-4152holdingthe VPP block. Does nothing on this firmware; 4148 accepted 65000 and did nothingown measurement, 2026-09-12
4048 / 4049holdinga dispatch pair. Does nothing in Custom or in thirdpartyEMS, with either signown measurement, 2026-09-12
3933not recordednot the thirdpartyEMS handshake: 11, 1, 3 and 0 changed nothing, 15 was rejectedown measurement, 2026-09-12
4000 / 4001not recordednot a clock but a last-sync stamp that stands still for minutesown measurement, 2026-09-12
3956read onlyshows the commanded power. On 12 September that was our confirmation; on 1 October it did not follow the command reliably. Confirm on 4985own measurement, 2026-09-12 and 2026-10-01

Holding 140 to 179: never write

⚠️Warning

Never write holding 140 to 179. That block does not change, is in no document and looks like the battery protection settings. The unit stores anything without checking it, and a lowered undervoltage limit is exactly how you force-charge an over-discharged cell. That these are protection settings is inferred from the values and not confirmed; that you do not write them is settled. derivedfrom the values in the block, read only for twelve hours while the cell voltage rose

On 26 September the block stayed the same for twelve hours while the cells rose by about 90 mV, so these are stored settings and not measured values. Reading is not always reliable here either: the unit drops a function code 3 read in this block now and then. Retry it. own measurementModbus reads, read only, with transaction id check · 26 September 2026

Behaviour a script has to handle

There is no watchdog and no command timeout. A written value stays until something overwrites it, also long after your script has stopped. So restore on exit and on a SIGTERM. The only limit the unit enforces itself is 4140. own measurementModbus writes · 12 September 2026

A change in the app takes minutes to reach the unit. If a register still shows the old value after a change in the app, read again later before you conclude it is the wrong register. own measurementModbus reads next to the app · 16 September 2026

In the undervoltage lockout, with 4979 at 7, it accepts commands and does not carry them out: writes are acknowledged and read back unchanged. The app then shows the mode that is requested and not what the battery management allows; the alarm list is the place to look. own measurementAEG StoragePRO 1.0.0 app and Modbus reads · 26 September 2026

The register map as CSV

Download aeg-solarcube-as-bbl08-modbus-registers.csv. One row per register, 46 rows, with the columns address, type (holding or input), name, unit_scale, access, what_it_does, status and source. Where HYXi uses a name of its own, it is in name. The status has five values:

The file is under CC BY 4.0: you may use, adapt and share it, also commercially, as long as you credit Jay's Desk and link to this page.

StatusMeaning
workschecked against the app, the metering socket or the behaviour of the unit
stored-onlyaccepts a value and stores it; we found no effect
do-not-writenever write
unconfirmedthe meaning or the reliability is not settled
misleadingdoes not do what the name or the value suggests

Every row comes from the same register map as the tables above.

What is still open

  • 4113 on the 3000 W setting, between 760 and 2850 W: not measured. And below 10: not measured.
  • 3956: reliable on 12 September, not on 1 October. Where the difference comes from is not settled.
  • 4112 is called MaxDischargeCurrent by HYXi. What it does on this unit is not settled.
  • 4024 = 1 and 2: which of the two self-consumption modes is which is not settled.
  • The four registers after start, end, mode and power in every slot.
  • What each bit in 5000 means, and what exactly 4109, 4110 and 4111 measure.
  • Firmware other than 331 / 259 / 286 / 259. The update the app offers did not install on this unit, so I do not know what changes after it.

How other brands handle reading and writing is in Controlling a home battery: what each brand lets you read, and what it lets you write. The specifications of this model are on the product card of the AEG SolarCube AS-BBL08 (in Dutch).

Frequently asked questions

Veelgestelde vragen

Does the AEG SolarCube Pro (AS-BBL08) have Modbus?+

Yes, over RS485 port D on the main unit: RJ45, pin 7 is A and pin 8 is B, 115200 baud, 8N1, unit id 1. It supports function codes 3, 4 and 16. We read it through an RS485 to Modbus TCP bridge, locally, without cloud and without an account. Checked on one unit, September 2026.

Does the Modbus document of HYXi or the HYXi HALO work for the AEG SolarCube?+

Not as a source of truth. The register layout is shared, the meaning differs: holding and input are different registers at the same addresses, and registers that look like a setpoint in the document do nothing here. Use HYXi's names as a lead and key a driver on the model string AS-BBL08-3K.

How do I set the discharge power over Modbus?+

Through the schedule table: work mode 4024 to 21 (Custom), 4178 to 1 or higher, 4179 to 127, 4180 to 1, and slot 0 in 4181 to 4184 to 0, 1440, 21 and the power in watts. Confirm on the DC power in 4985. An empty schedule discharges 200 W; to stand still, set the slot to 0 W.

How do I set the charge power over Modbus?+

With a forced charge: 4021 to 1, 4132 above the current state of charge, 4140 to the stop state of charge, and 4113 as the limit. On the 800 W setting that is about 19 W per step: 10 gave 192 W and 40 gave 752 W, measured on 1 October 2026. The app does not show this limit, and a slot in the schedule table does not charge.

Can I set the 800 or 3000 W grid setting over Modbus?+

No, no register writes it; the setting lives only in the app. Registers 5021 and 5023 show the setting times 0.95, so 760 or 2850 W, but only while the unit is connected to the grid.

Which registers must I not write?+

Holding 140 to 179: that block looks like the battery protection settings, and the unit stores any value without checking it. Also write nothing in 4024 outside the known work modes, because it stores anything there too.

Can I control the AEG SolarCube with Home Assistant?+

We have not tested it with an existing integration. Over Modbus TCP, Home Assistant can read and write; control discharge through the schedule table and charge through 4132, 4140 and 4113, and add a restore on exit, because the unit has no watchdog.

Sources

Bronnen

  1. [1]Our techbench: register map AEG AS-BBL08-3KBuilt from 12 to 30 September 2026 by checking every register against the app, the metering socket or the behaviour of the unit, on firmware 331 / 259 / 286 / 259. Extended on 1 October 2026 with 4113, 4178, the unsigned power in the slots, 4118 to 4120 and 3956. Source of every row marked own measurement and of the CSV file.
  2. [2]Our techbench: limited charging with register 4113, 1 October 2026Forced charge on the 800 W setting at a state of charge of about 71 %, with 4113 at 10, 20, 30, 40 and 50 and up; DC power from 4985 and the metering socket on the grid side.
  3. [3]AEG, user manual AS-BBL08 series V1.0-26 (EN)Archived as content/productblad/aeg-solarcube-as-bbl08/handleiding-PD202602-v1.0-26-en.pdf. Page 9 (PDF page 12), port legend: D is the RS485 port, a network-cable port for a third-party energy manager. The text of the manual says nothing about Modbus, the pins or the serial settings.
  4. [4]AEG SolarCube AS-BBL08, datasheet V2.0 (EN, January 2026)Retrieved 12-09-2026. Communication row: WiFi / Bluetooth / CAN; footnote 5 makes CAN the line to the battery module. The RS485 port is not in the specification table.
  5. [5]HYXi, Micro Storage RS485 MODBUS V1.0The builder's register document, as its register table is reproduced in the ha-hyxi-cloud repository. Source of part of the HYXi names on this page. It does not hold for this unit, also where the addresses match.
  6. [6]AEG StoragePRO 1.0.0, the appSource of the work modes, the schedule table in Custom, the notice that empty time slots deliver 200 W by default, and the 800 or 3000 W grid setting. Seen from 12 September to 1 October 2026.
Video thumbnail: Plug-in batteries lead the Dutch market. And nobody is counting them.

Newest on Jay's Desk

Plug-in batteries lead the Dutch market. And nobody is counting them.

The videos behind these articles. Same numbers, same sources, on video.

You might also enjoy

Related articles

energieaeg

AEG SolarCube Pro error 170305110: what “Head unit undervoltage, level-3 fault” means

Error 170305110, Head unit undervoltage, level-3 fault, means the battery of the AEG SolarCube Pro is discharged too deeply and the battery management system has locked it. For days the app then says Battery Force Charging Mode while 2 to 6 W goes in. Our unit drained itself off the grid, sat locked for 4 days and 5 hours after it was plugged back in, and came out on its own. What each message means, why it drains while it looks switched off, and what does and does not help.

JJooshua··17 min read
energieaeg

AEG SolarCube Pro tested: what comes out of this unit, and where the rest goes

The AEG SolarCube Pro costs € 1,799 and promises 6.0 kWh usable and a single efficiency figure. We hooked it up to our techbench for two days, walked the whole discharge curve by hand and closed the cycle: 1,165 Wh went in and 947 Wh came out. After the test, off the grid, it drained itself until the battery management system locked it out, and it only came out of that by itself 4 days and 5 hours later. Here is the full file behind the video: every figure with its origin and grid setting, the registers we mapped ourselves, the places where the product sheets contradict each other, and the fifteen things I do not know yet.

JJooshua··60 min read
energiestekkerbatterij

Trading with a plug-in battery: it works, just not where your salesperson thinks

Salespeople say a plug-in battery can't trade. That's true for one of the three meanings of that word, and not for the other two. Here's which brands you can control locally, why your energy supplier is the real bottleneck, and why a cheap hour can still cost you money — with the 590-day backtest that backs it up.

JJooshua··18 min read
energiethuisbatterij

Controlling a home battery: what each brand lets you read, and what it lets you write

Almost every home battery lets you watch. A much smaller number lets you change anything. This is the full dossier behind the video: the endpoint or register per brand, the firmware version it applies to, the verification date, and the arithmetic that shows why an 800-watt setpoint rarely pulls 800 watts out of your battery.

JJooshua··23 min read