AEG SolarCube Pro Modbus registers (AS-BBL08 / HYXi HALO): what works and what only stores
The AEG SolarCube Pro (AS-BBL08) has an RS485 port that speaks Modbus, locally and without an account, but we found no register document that matches this unit. This is the register map we built ourselves and checked register by register against the unit: how to connect, which registers work, how to control charge and discharge, which registers store a value and do nothing, and which block you never write. The whole map is also available as a CSV download.
In this article14
- Connecting to the RS485 port of the AEG SolarCube
- Holding and input are two separate spaces
- Identity: model string, firmware and rated power
- Live values: state of charge, power and cells
- Work mode, on and off
- Controlling discharge: the schedule table from 4178
- Controlling charge: forced charge with 4132, 4140 and 4113
- Registers that store a value and do nothing
- Holding 140 to 179: never write
- Behaviour a script has to handle
- The register map as CSV
- What is still open
- Frequently asked questions
- Sources
TL;DR
The AEG SolarCube Pro, model number AS-BBL08, has an RS485 port on the back that speaks Modbus. We found no register document from AEG or HYXi that matches this unit. HYXi builds it, and it is an AEG-badged HYXi HALO: the register layout is shared, the meaning of the registers is not. own measurementModbus reads over RS485, set against HYXi's register document · 12 September 2026 This page lists the Modbus registers we mapped ourselves, each one checked against the app, the metering socket or the behaviour of the unit. What the battery itself delivers is in the AEG SolarCube Pro review. This page is only about reading and control.
The whole map is also in one file: aeg-solarcube-as-bbl08-modbus-registers.csv, 46 rows. What the columns mean is at the bottom, with the download.
ℹ️Info
This map holds for one unit, with firmware 331 / 259 / 286 / 259 and control software V01.03.01.1E. We have not seen another version. After an update an address can move or a meaning can change. So check every register against your own unit before you control it. own measurementModbus reads over RS485, each register checked against app, meter or behaviour · 30 September 2026
Connecting to the RS485 port of the AEG SolarCube
The port is D, on the main unit. The manual describes it as a standard network-cable port for a third-party energy manager to control your system. manufacturerAS-BBL08 user manual V1.0-26, page 9, port legend The specification table of the datasheet does not list it. It says "WiFi / Bluetooth / CAN", and footnote 5 makes CAN the line to the battery module. manufacturerdatasheet V2.0, communication row and footnote 5 · 12 September 2026
| Setting | Value | Source |
|---|---|---|
| Port | D, RS485, an RJ45 socket on the main unit | manufacturer, manual p. 9 |
| Wires | pin 7 = A, pin 8 = B; in T568B that is white-brown and brown | own measurement, 2026-09-12 |
| Serial settings | 115200 baud, 8N1 | own measurement, 2026-09-12 |
| Unit id | 1; it answers on every unit id as itself, the packs have no address of their own | own measurement, 2026-09-12 |
| Function codes | 3 (read holding), 4 (read input), 16 (write) | own measurement, 2026-09-12 |
| Path | RS485 to Modbus TCP through a bridge; no cloud and no account | own measurement, 2026-09-25 |
Our bridge was a USR-W610 in Modbus TCP to RTU translation mode. In that mode, use plain Modbus TCP framing (MBAP); RTU over TCP timed out for us. At 9600 baud the bus stays dead. If two programs share the same bridge, check the transaction id on every reply. Without that check one program receives the other's answers, and on 25 September that gave us a scan in which whole blocks sat 150 to 200 registers out of place. own measurementModbus TCP through a USR-W610 to RS485
Other function codes time out: 43/14 (device identification), 20 (file record), 17 and 8. Coils and discrete inputs (function codes 1 and 2) do not exist anywhere between 0 and 9999. So there is no way to update the firmware over Modbus. own measurementModbus scan over RS485
Control over this port needs no internet. It is also the only local path: the communication module has every port closed on the home network and talks only to the cloud. own measurementModbus TCP through an RS485 bridge, and a port scan of the communication module · 25 September 2026
Holding and input are two separate spaces
On this unit, holding (function code 3) and input (function code 4) are different registers, also where the address is the same. Input 4048 and 4049 are the rated frequency and voltage; holding 4048 and 4049 is a dispatch pair that does nothing. HYXi's register document does not make that distinction. own measurementModbus reads and a write test · 12 September 2026
Above 9999 it gives well-formed replies with no content on function codes 3 and 4. A scanner that counts every reply without an exception as a hit finds about thirty false islands there. own measurementModbus scan over RS485, 10000 to 65535
Where HYXi uses a name of its own for a register, in its register document or in the firmware, that name is in the tables and in the CSV. Such a name is a lead, not proof. The HYXi document we found, Micro Storage RS485 MODBUS V1.0, does not hold for this unit, also where the addresses match. So do not use it to correct this map. If you build a driver, key it on the model string AS-BBL08-3K and never on "HALO". Then a HYXi-badged unit does not silently inherit the behaviour of this AEG. own measurementModbus reads, register by register next to HYXi's document · 12 September 2026
Identity: model string, firmware and rated power
| Register | Space | What it does | Source |
|---|---|---|---|
| 4002-4007 | input | model string, two characters per register with the bytes swapped: AS-BBL08-3K | own measurement, 2026-09-12 |
| 3100 / 3180 | input | internal model name, also byte-swapped: HYX-MS3000B | own measurement |
| 4026-4029 | input | firmware versions, here 331 / 259 / 286 / 259; 4027 = 0x103 and 4028 = 0x11E match control software V01.03.01.1E in the app | own measurement, 2026-09-12 |
| 4046 | input | rated power: 3000 W | own measurement, 2026-09-12 |
| 4048 / 4049 | input | rated frequency and voltage, times 0.01: 50.00 Hz and 230.0 V | own measurement, 2026-09-12 |
| 4978 | input | the number of packs that report, 1 or 2 | own measurement, 2026-09-25 |
| 4981 | input | always 1000. Not capacity. HYXi calls it soh; 100.0 % state of health fits, but it is not verified | own measurement, 2026-09-27 |
Every text we read in the registers had the two bytes of each register swapped. Swap them back before you compare the string.
Live values: state of charge, power and cells
| Register | Space | What it does | Source |
|---|---|---|---|
| 3030 / 3130 | input | state of charge of pack 1 and pack 2, in tenths of a percent. The reliable source: 491 read as 49.1 % against 49 % in the app | own measurement, 2026-09-12 |
| 3033 / 3133 | input | state of health of pack 1 and pack 2, in percent | own measurement, 2026-09-12 |
| 3035 / 3135 | input | power per pack, signed watts; together within 3 W of 4985 | own measurement, 2026-09-12 |
| 3034 / 3134 | input | a second power pair; together about 12 W above the measured DC power. Do not add it up | own measurement, 2026-09-12 |
| 3039 / 3139 | input | highest cell voltage of pack 1 and pack 2, in mV | own measurement, 2026-09-12 |
| 3040 / 3140 | input | lowest cell voltage of pack 1 and pack 2, in mV | own measurement, 2026-09-12 |
| 3045 / 3145 | input | warmest cell, in tenths of a degree | own measurement, 2026-09-12 |
| 3046 / 3146 | input | coldest cell, in tenths of a degree | own measurement, 2026-09-12 |
| 4985 | input | battery DC power, 32-bit, low word first; positive is discharge, negative is charge | own measurement, 2026-09-12 |
| 4152 | input | AC power, mirrored at 4163; positive is export. Not usable near zero | own measurement, 2026-09-12 |
| 5021 / 5023 | input | maximum discharge and charge power, 32-bit, low word first: the grid setting times 0.95, so 760 or 2850 W | own measurement, 800 W and 3000 W settings, 2026-09-12 |
| 4151 | input | grid frequency, times 0.01: 4997 is 49.97 Hz | own measurement |
| 4161 / 4210 | input | grid voltage, times 0.01: 23426 is 234.26 V | own measurement |
| 4982 | input | not the state of charge. It read 39 to 46 % while the packs were at 48 to 49 %, and it moves independently of charging | own measurement |
Control on the lower of 3030 and 3130. 4982 looks like a state of charge and cost us most of a session before we saw that it is not one. own measurementModbus reads next to the app · 12 September 2026
5021 and 5023 report what the unit can do at that moment, not the setting in the app. Off the grid and just after reconnecting they fall away. A script that reads a ceiling from them before it starts then aborts for no reason or commands too little. Read them only once 4979 is at 4. own measurementModbus reads while disconnecting and reconnecting, 800 W grid setting · 12 September 2026 No register writes the grid setting itself, 800 or 3000 W. It lives only in the app. own measurementModbus reads and app, 800 W and 3000 W grid settings · 12 September 2026
Work mode, on and off
| Register | Space | What it does | Source |
|---|---|---|---|
| 4021 | holding | on and off: 1 = on, 3 = standby, 0 = while booting. A 2 is acknowledged and reads back as 3; there is no deeper off | own measurement, 2026-09-30 |
| 4024 | holding | work mode: 3 = Backup, 21 = Custom, 22 = Time of Use, 23 = thirdpartyEMS. 1 and 2 are the two self-consumption modes; which is which is not settled. It stores any value, so write nothing outside this list | own measurement, 2026-09-12 |
| 4102 | input | the mode the app shows, including a mode the firmware imposes. Not a mirror of 4024 | own measurement |
| 4979 | input | connection state: 4 = connected to the grid, 3 and 5 = retrying before connecting, 11 = briefly while reconfiguring, 7 = locked out on battery undervoltage | own measurement, 2026-09-25 |
| 5000 | input | the battery alarm word, mirrored at 3050. What each bit means is not established | own measurement, 2026-09-25 |
| 4109 / 4110 / 4111 | input | probably temperatures in the inverter, in tenths of a degree. The meaning is not confirmed | own measurement |
The thirdpartyEMS mode reports itself as such and accepts a power value by no path we tried. Custom, with the schedule table below, is the mode in which you set a discharge power over Modbus. own measurementModbus writes, mode by mode · 12 September 2026
Standby is not off. With 4021 at 3 it draws about 9.5 W, and with the power button off 9.3 W; Modbus keeps answering in both cases. Off the grid, that draw comes from the battery. own measurementmetering socket and Modbus reads, after the recovery · 30 September 2026 That is how our unit drained until the battery management locked it out. What the error code then means and how it came back is on the page about error code 170305110.
Controlling discharge: the schedule table from 4178
It has no power setpoint register. You control discharge through the schedule table the app itself uses in Custom mode. The proof that it is the same table: when the app held three time slots of 15, 30 and 45 W, exactly those values with exactly those boundaries sat in 4181 to 4200, in a change we had not written over the bus. own measurementModbus reads next to the app · 12 September 2026
4024 = 21 work mode Custom
4178 = 1 PeriodNum: 1 or higher, or the schedule reads as empty
4179 = 127 days as a bitmask, 127 = every day
4180 = 1 the number of slots
4181, 4182, 4183, 4184 slot 0: start, end, mode, power
= 0, 1440, 21, <watts> start and end in minutes of the day
Slot n starts at 4181 + 8n and takes eight registers. The first four are start, end, mode and power; what the other four do is not settled. The mode in the slot takes the same values as 4024. own measurementModbus writes, confirmed on 4985 · 1 October 2026
We never wrote 4178 at first. On our unit it sat at 0 after a full reset, the whole schedule read as empty and the unit delivered the 200 W default, so every slot write looked ignored. So always set it. own measurementModbus writes after a full reset · 1 October 2026
The power in a slot is an unsigned discharge power. A slot does not charge. If you write a negative number, it reads it as a large positive one and discharges at its maximum. own measurementModbus writes, confirmed on 4985, 800 W grid setting · 1 October 2026
An empty schedule is not zero. With no valid slot it discharges 200 W; the app itself warns about it. To make it stand still, set one all-day slot to 0 W: 4180 = 1 and slot 0 = [0, 1440, 21, 0]. own measurementModbus reads and the notice in the app · 16 September 2026
What you write into the slots over the bus is lost on a full reset. The schedule set in the app survives that reset. Give every script a restore on exit, and set the slot power to 0 there instead of commanding a previously captured power again. own measurementModbus reads before and after a full reset · 16 September 2026
Controlling charge: forced charge with 4132, 4140 and 4113
You cannot pick the charge power in the app, and not in a slot either. Over Modbus you can, with a forced charge:
- Set
4021to 1. From standby a forced charge does nothing, and the grid has to be connected. - Set
4132, the start state of charge, above the current state of charge. It then charges at the grid setting. - Set
4140, the stop state of charge, to your target. The unit enforces that limit itself, also when the script that controls it stops halfway. - Set
4113to the limit you want.
4113 limits the charge power only while a forced charge runs, and the relation is linear: about 19 W per step, from about 190 W up to the ceiling of the grid setting. During discharge 4113 does nothing. HYXi calls the register MaxChargeCurrent. Which unit the device reads into it is not settled, so work with what was measured.
≈ 19 W
charge power per step in register 4113, during a forced charge
Bron: own measurement, 800 W grid setting, 1 October 2026
4113 | Charge power, DC | Source |
|---|---|---|
| 10 | 192 W | own measurement, 800 W setting, 2026-10-01 |
| 20 | 382 W | own measurement, 800 W setting, 2026-10-01 |
| 30 | 569 W | own measurement, 800 W setting, 2026-10-01 |
| 40 | 752 W | own measurement, 800 W setting, 2026-10-01 |
| 50 and up | 760 W, the ceiling of the 800 W setting | own measurement, 800 W setting, 2026-10-01 |
It worked on the unit itself and it is reversible: one write took it from discharging to charging. Values below 10 are not in our measurement, and on the 3000 W setting, between 760 and 2850 W, we did not measure 4113. own measurementour techbench, metering socket, Modbus writes to 4113 during a forced charge, 800 W grid setting · 1 October 2026
| Register | Space | What it does | Source |
|---|---|---|---|
| 4132 | holding | forced charge, start state of charge in percent (force_charge_start_soc) | own measurement, 2026-09-12 |
| 4140 | holding | forced charge, stop state of charge in percent, enforced by the unit itself (force_charge_stop_soc) | own measurement, 2026-09-12 |
| 4113 | holding | charge limit during a forced charge, about 19 W per step (MaxChargeCurrent) | own measurement, 800 W setting, 2026-10-01 |
| 4121 | holding | anti-starvation protection, 1 = on (anti_starvation). Charges from the grid, so off the grid it does nothing | own measurement, 2026-09-27 |
| 4133 | holding | minimum state of charge for off-grid, in whole percent (off_grid_min_soc) | own measurement, 2026-09-27 |
| 4134 | holding | minimum state of charge for self-consumption, in whole percent (self_use_soc) | own measurement, 2026-09-27 |
| 4141 | holding | minimum state of charge for discharge, in whole percent (discharge_min_soc). Applies to discharge, not to what the unit uses itself | own measurement, 2026-09-27 |
None of these limits is a voltage limit. They are states of charge. own measurementModbus reads of the settings, holding 4121 to 4141 · 27 September 2026
Registers that store a value and do nothing
The unit does not check a write when it receives it, only when it executes it. A successful read-back proves storage, not obedience: 4148 accepted 65000. After every write, look at the DC power in 4985, and never only at the read-back straight after it. own measurementModbus writes and reads, register by register · 12 September 2026
| Register | Space | What happens | Source |
|---|---|---|---|
| 3961 | holding | stores and reads back, controls nothing. It looked like a power register while a slot happened to hold the same power | own measurement, 2026-09-12 |
| 4118-4120 | holding | BatterySetPower and BatteryForceControlEnable in HYXi's naming. Accepts a value and keeps it; nothing in this firmware acts on it. Not the charge path | own measurement, 2026-10-01 |
| 4146-4152 | holding | the VPP block. Does nothing on this firmware; 4148 accepted 65000 and did nothing | own measurement, 2026-09-12 |
| 4048 / 4049 | holding | a dispatch pair. Does nothing in Custom or in thirdpartyEMS, with either sign | own measurement, 2026-09-12 |
| 3933 | not recorded | not the thirdpartyEMS handshake: 11, 1, 3 and 0 changed nothing, 15 was rejected | own measurement, 2026-09-12 |
| 4000 / 4001 | not recorded | not a clock but a last-sync stamp that stands still for minutes | own measurement, 2026-09-12 |
| 3956 | read only | shows the commanded power. On 12 September that was our confirmation; on 1 October it did not follow the command reliably. Confirm on 4985 | own measurement, 2026-09-12 and 2026-10-01 |
Holding 140 to 179: never write
⚠️Warning
Never write holding 140 to 179. That block does not change, is in no document and looks like the battery protection settings. The unit stores anything without checking it, and a lowered undervoltage limit is exactly how you force-charge an over-discharged cell. That these are protection settings is inferred from the values and not confirmed; that you do not write them is settled. derivedfrom the values in the block, read only for twelve hours while the cell voltage rose
On 26 September the block stayed the same for twelve hours while the cells rose by about 90 mV, so these are stored settings and not measured values. Reading is not always reliable here either: the unit drops a function code 3 read in this block now and then. Retry it. own measurementModbus reads, read only, with transaction id check · 26 September 2026
Behaviour a script has to handle
There is no watchdog and no command timeout. A written value stays until something overwrites it, also long after your script has stopped. So restore on exit and on a SIGTERM. The only limit the unit enforces itself is 4140. own measurementModbus writes · 12 September 2026
A change in the app takes minutes to reach the unit. If a register still shows the old value after a change in the app, read again later before you conclude it is the wrong register. own measurementModbus reads next to the app · 16 September 2026
In the undervoltage lockout, with 4979 at 7, it accepts commands and does not carry them out: writes are acknowledged and read back unchanged. The app then shows the mode that is requested and not what the battery management allows; the alarm list is the place to look. own measurementAEG StoragePRO 1.0.0 app and Modbus reads · 26 September 2026
The register map as CSV
Download aeg-solarcube-as-bbl08-modbus-registers.csv. One row per register, 46 rows, with the columns address, type (holding or input), name, unit_scale, access, what_it_does, status and source. Where HYXi uses a name of its own, it is in name. The status has five values:
The file is under CC BY 4.0: you may use, adapt and share it, also commercially, as long as you credit Jay's Desk and link to this page.
| Status | Meaning |
|---|---|
| works | checked against the app, the metering socket or the behaviour of the unit |
| stored-only | accepts a value and stores it; we found no effect |
| do-not-write | never write |
| unconfirmed | the meaning or the reliability is not settled |
| misleading | does not do what the name or the value suggests |
Every row comes from the same register map as the tables above.
What is still open
4113on the 3000 W setting, between 760 and 2850 W: not measured. And below 10: not measured.3956: reliable on 12 September, not on 1 October. Where the difference comes from is not settled.4112is calledMaxDischargeCurrentby HYXi. What it does on this unit is not settled.4024= 1 and 2: which of the two self-consumption modes is which is not settled.- The four registers after start, end, mode and power in every slot.
- What each bit in
5000means, and what exactly4109,4110and4111measure. - Firmware other than 331 / 259 / 286 / 259. The update the app offers did not install on this unit, so I do not know what changes after it.
How other brands handle reading and writing is in Controlling a home battery: what each brand lets you read, and what it lets you write. The specifications of this model are on the product card of the AEG SolarCube AS-BBL08 (in Dutch).
Frequently asked questions
Veelgestelde vragen
Does the AEG SolarCube Pro (AS-BBL08) have Modbus?+
Yes, over RS485 port D on the main unit: RJ45, pin 7 is A and pin 8 is B, 115200 baud, 8N1, unit id 1. It supports function codes 3, 4 and 16. We read it through an RS485 to Modbus TCP bridge, locally, without cloud and without an account. Checked on one unit, September 2026.
Does the Modbus document of HYXi or the HYXi HALO work for the AEG SolarCube?+
Not as a source of truth. The register layout is shared, the meaning differs: holding and input are different registers at the same addresses, and registers that look like a setpoint in the document do nothing here. Use HYXi's names as a lead and key a driver on the model string AS-BBL08-3K.
How do I set the discharge power over Modbus?+
Through the schedule table: work mode 4024 to 21 (Custom), 4178 to 1 or higher, 4179 to 127, 4180 to 1, and slot 0 in 4181 to 4184 to 0, 1440, 21 and the power in watts. Confirm on the DC power in 4985. An empty schedule discharges 200 W; to stand still, set the slot to 0 W.
How do I set the charge power over Modbus?+
With a forced charge: 4021 to 1, 4132 above the current state of charge, 4140 to the stop state of charge, and 4113 as the limit. On the 800 W setting that is about 19 W per step: 10 gave 192 W and 40 gave 752 W, measured on 1 October 2026. The app does not show this limit, and a slot in the schedule table does not charge.
Can I set the 800 or 3000 W grid setting over Modbus?+
No, no register writes it; the setting lives only in the app. Registers 5021 and 5023 show the setting times 0.95, so 760 or 2850 W, but only while the unit is connected to the grid.
Which registers must I not write?+
Holding 140 to 179: that block looks like the battery protection settings, and the unit stores any value without checking it. Also write nothing in 4024 outside the known work modes, because it stores anything there too.
Can I control the AEG SolarCube with Home Assistant?+
We have not tested it with an existing integration. Over Modbus TCP, Home Assistant can read and write; control discharge through the schedule table and charge through 4132, 4140 and 4113, and add a restore on exit, because the unit has no watchdog.
Sources
Bronnen
- [1]Our techbench: register map AEG AS-BBL08-3KBuilt from 12 to 30 September 2026 by checking every register against the app, the metering socket or the behaviour of the unit, on firmware 331 / 259 / 286 / 259. Extended on 1 October 2026 with 4113, 4178, the unsigned power in the slots, 4118 to 4120 and 3956. Source of every row marked own measurement and of the CSV file.
- [2]Our techbench: limited charging with register 4113, 1 October 2026Forced charge on the 800 W setting at a state of charge of about 71 %, with 4113 at 10, 20, 30, 40 and 50 and up; DC power from 4985 and the metering socket on the grid side.
- [3]AEG, user manual AS-BBL08 series V1.0-26 (EN)Archived as content/productblad/aeg-solarcube-as-bbl08/handleiding-PD202602-v1.0-26-en.pdf. Page 9 (PDF page 12), port legend: D is the RS485 port, a network-cable port for a third-party energy manager. The text of the manual says nothing about Modbus, the pins or the serial settings.
- [4]AEG SolarCube AS-BBL08, datasheet V2.0 (EN, January 2026)Retrieved 12-09-2026. Communication row: WiFi / Bluetooth / CAN; footnote 5 makes CAN the line to the battery module. The RS485 port is not in the specification table.
- [5]HYXi, Micro Storage RS485 MODBUS V1.0The builder's register document, as its register table is reproduced in the ha-hyxi-cloud repository. Source of part of the HYXi names on this page. It does not hold for this unit, also where the addresses match.
- [6]AEG StoragePRO 1.0.0, the appSource of the work modes, the schedule table in Custom, the notice that empty time slots deliver 200 W by default, and the 800 or 3000 W grid setting. Seen from 12 September to 1 October 2026.
