Skip to content

Revo 3 Communication Protocol

This page is for developers who access Revo 3 registers directly over RS485 or CAN FD. Revo3 SDK applications should use the physical units defined by the API. The SDK already handles register scaling, byte order, CRC, and CAN FD frame encapsulation; do not apply those conversions again.

The motion registers documented here use Revo3 Ultra (21 DOF) as the baseline. Before integrating another Revo 3 model, read and verify the joint count and order reported by JointLayout. Do not send a 21-joint control frame to an unvalidated layout.

Before writing registers

Confirm the device ID, model, firmware version, and joint layout. Before writing configuration or motion registers, keep people and obstacles outside the hand workspace and provide a way to remove actuator power independently of software control.

1. Supported interfaces

InterfaceTransport
RS485Modbus RTU
CAN FDComplete Modbus RTU frames encapsulated in CAN FD extended frames

2. Modbus RTU

Revo 3 RS485 communication uses the standard Modbus RTU frame format.

2.1 Frame Format

Header / Device IDFunction CodeDataCRC16
1 Byte1 ByteN Bytes2 Bytes

2.2 Field Descriptions

FieldDescription
Header/Device IDSlave device address
Function CodeModbus function code (e.g., 03H: Read Holding Registers; 04H: Read Input Registers; 06H: Write Single Holding Register; 10H: Write Multiple Holding Registers)
DataData payload, varying based on the function code and register address
CRC16CRC-16 (Modbus) checksum, low byte first, high byte last

The commonly supported function codes are 0x03 (Read Holding Registers), 0x04 (Read Input Registers), 0x06 (Write Single Holding Register), and 0x10 (Write Multiple Holding Registers). Write a multi-register command in one complete 0x10 request; do not split it into single-register requests that the device could execute separately.


3. CAN FD Encapsulation Format

When using the CAN FD interface, the underlying communication still contains Modbus protocol data, which is encapsulated and transmitted within a 29-bit CAN FD extended frame.

The CAN FD arbitration rate is fixed at 1 Mbps. The data phase supports 1, 2, 4, and 5 Mbps, with 5 Mbps as the default.

3.1 CAN FD ID Format

The 29-bit CAN FD ID is allocated as follows:

BitsFieldDescription
28 ~ 24ReservedFixed to 0
23 ~ 16Device IDSlave device address
15 ~ 8Master IDHost device ID (defined by host)
7 ~ 0Payload LengthActual length of active data payload (Bytes)

Default Device ID

DeviceDefault Device ID (Decimal)Default Device ID (Hexadecimal)
Left Hand1260x7E
Right Hand1270x7F

3.2 Frame Formats

Host Transmission Frame

CAN FD ID (29-bit)Data Segment (Payload, ≤ 64 Bytes)
Device ID + Master ID + Payload LengthComplete Modbus RTU request frame (including checksums)

Device Reply Frame

CAN FD ID (29-bit)Data Segment (Payload, ≤ 64 Bytes)
Device ID + Master ID + Payload LengthComplete Modbus RTU response frame

Payload Length is the actual size of the complete Modbus RTU frame in the CAN FD data field, including Device ID, function code, data, and CRC16. The maximum is 64 Bytes.

When a supported broadcast request is used, a response carries the hand's own Device ID rather than the broadcast ID. Broadcast applies only to RS485 integrations that explicitly support it. CAN FD uses the distinct 0x7E / 0x7F hand IDs and does not support Device ID 0 broadcast.


4. Register Map Overview

Revo 3 registers are grouped by function as follows:

Address RangeRegister TypeCategory
0 ~ 199Holding RegisterSystem Configuration
200 ~ 399Holding RegisterMotor Parameters
500 ~ 573Holding RegisterFirmware Update (SDK-managed; packet details are not public)
1000 ~ 1599Holding RegisterControl Commands
1800 ~ 1999Input RegisterSystem Status
2030 ~ 2999Input RegisterMotor Feedback
3000 ~ 3999Input RegisterDevice Information
4000 ~ 4751Holding / Input RegisterPiezoresistive array touch modules
5003 ~ 5910Holding / Input RegisterHigh-density tactile array modules
6500 ~ 6709Holding / Input RegisterFingertip force/torque touch modules

5. System Configuration Registers

System configuration registers (address range 0~199) support read/write access.

AddressNameAccessDescription
60 ~ 80Motor Zero OffsetRWUnit: 0.01° (transmitted as value × 100). Total 21 joints.
81Set Current Position as ZeroWOWrite 1; verify that the mechanical position is safe first.
101Hand IdentityRO1 = Right hand, 2 = Left hand
102Restore Finger DefaultsWOWrite specific value to restore default finger parameters.
105Buzzer SwitchRW0 = Off, 1 = On
106Vibration Motor SwitchRW0 = Off, 1 = On
107Touch Screen SwitchRW0 = Off, 1 = On
108Device IDRWDefault: 126 for Left hand, 127 for Right hand
109RS485 BaudrateRWSee 5.1 RS485 Baudrate
110CAN FD BaudrateRWSee 5.2 CAN FD Baudrate
111Software RebootWOWrite 1 to reboot the device.
112Auto CalibrationRW0 = Off, 1 = On (automatically run calibration on boot)
113Joint Position CalibrationWOWrite 1; do not send motion commands while calibration is active.
114Calibration CurrentWOWrite the calibration-current value; prefer the SDK Calibration API.
117Clear Motor FaultsWOWrite 1; remove the fault cause before clearing.
118Teaching ModeRWWrite 1 to enter, 0 to exit
119Software StopRWWrite 1 to stop and 0 to recover. This is not a functional-safety emergency stop.
120Use Broadcast IDRW1 = Enabled (default), 0 = Disabled. See the CAN FD broadcast limitation.
131Auto-clear Motor ErrorRW0 = Off (default), 1 = On

5.1 RS485 Baudrate

ValueBaudrate
01 Mbps
12 Mbps
23 Mbps
45 Mbps (default)

5.2 CAN FD Baudrate

ValueBaudrate
01 Mbps
12 Mbps
24 Mbps
35 Mbps

6. Motor Parameters

The units for motor parameters are defined as follows:

  • Position: Degrees (°)
  • Velocity: Revolutions per minute (rpm)
  • Current: Milliamperes (mA)

💡 Numerical Scaling Details

To maintain data precision, position and velocity values are transmitted as integers using actual value × 100.

  • Angle Example: Target position 90.00° → transmitted register value is 9000.
  • Velocity Example: Target velocity 50.00 rpm → transmitted register value is 5000.
  • Current Example: Target protection currents directly use the physical value in mA.

6.1 Global Protection Current

AddressParameterAccessDescription
200All Joints Protection Current (mA)WOConfigures protection current for all 21 joints at once

6.2 Single Joint Protection Current

AddressParameterAccessDescription
201 ~ 221Joint Protection Current (mA)RWMaximum allowed current for joints 0 to 20

6.3 Joint Movement Limits

AddressParameterAccessDescription
240 ~ 260Min Position Limit (° × 100)RWPhysical minimum position limit for joints 0 to 20
270 ~ 290Max Position Limit (° × 100)RWPhysical maximum position limit for joints 0 to 20
300 ~ 320Min Velocity Limit (rpm × 100)RWMinimum speed limit for joints 0 to 20
321 ~ 341Max Velocity Limit (rpm × 100)RWMaximum speed limit for joints 0 to 20

7. Control Commands

Revo 3 supports position, velocity, current, impedance, damping, and MIT control. A command can move a joint immediately. During initial commissioning, limit current and velocity and keep people and obstacles outside the workspace.

7.1 General Control Modes

ValueModeControl Parameter
0PositionTarget angle (° × 100)
1VelocityTarget velocity (rpm × 100)
2CurrentTarget current (mA)
4ImpedanceImpedance coefficient (value × 100)
5DampingDamping coefficient (value × 100)

7.2 General Control Registers

AddressParameterDescription
1000Joint ID0~20 on Revo3 Ultra
1001Control ModeUses the value from 7.1
1002Control ParameterEncoding depends on the selected mode
1010Multi-joint Control ModeUses the value from 7.1
1011 ~ 103121 Joint ParametersOrdered by joint ID; use only according to the active JointLayout
1500Four-finger Index1 = Index, 2 = Middle, 3 = Ring, 4 = Pinky
1501Four-finger Control ModeUses the value from 7.1
1502 ~ 1505Four-finger Parameters[Abduction MCP, MCP, PIP, DIP]
1510Thumb Control ModeUses the value from 7.1
1511 ~ 1515Thumb ParametersLogical order [Rotation, MCP, IP, Abduction, Flexion], corresponding to J16~J20

7.3 MIT Control Formula

τ=Kp×(PosRefPos)+Kd×(VelRefVel)+τff

Data Scaling

  • Kp, Kd, Position, Velocity are transmitted as actual value × 100.
  • Current (τff) is transmitted directly in mA.

Example:

  • Kp target = 5.00 transmitted value = 500
  • Kd target = 0.50 transmitted value = 50
  • Position target = 90.00° transmitted value = 9000
  • Velocity target = 50.00 rpm transmitted value = 5000
  • Current (τff) target = 1000 mA transmitted value = 1000

7.4 Single Joint MIT Control

Enables standalone control of a specific joint:

AddressParameterDescription
1050Joint IDTarget joint number (0 ~ 20)
1051KpProportional stiffness gain (value × 100)
1052KdDerivative damping gain (value × 100)
1053PositionTarget position (° × 100)
1054VelocityTarget velocity (rpm × 100)
1055Current (τff)Feedforward current (mA)

7.5 Multi-Joint MIT Control

Provides a continuous register map block for bulk updates of multiple joints:

Address RangeTarget JointParameter ArrayDescription
1100 ~ 1104Joint 0[Kp,Kd,Pos,Vel,τff]5 consecutive registers
1105 ~ 1109Joint 1[Kp,Kd,Pos,Vel,τff]5 consecutive registers
............
1195 ~ 1199Joint 19[Kp,Kd,Pos,Vel,τff]5 consecutive registers
1200 ~ 1204Joint 20[Kp,Kd,Pos,Vel,τff]5 consecutive registers

7.6 Bulk Parameter Controls

Enables targeted bulk updates for a single MIT parameter across all joints:

Address RangeParameterDescription
1300 ~ 1320Kp ListProportional gain (Kp) for all 21 joints
1321 ~ 1341Kd ListDamping gain (Kd) for all 21 joints
1342 ~ 1362Position ListTarget position (Pos) for all 21 joints
1363 ~ 1383Velocity ListTarget velocity (Vel) for all 21 joints
1384 ~ 1404τff ListFeedforward current (τff) for all 21 joints

7.7 Four-Finger MIT Control

Used to control the index, middle, ring, or pinky finger:

AddressParameterDescription
1520Finger Index1 = Index, 2 = Middle, 3 = Ring, 4 = Pinky
1521 ~ 1540Parameter ArrayTotal 20 registers containing gains and references:
1. Abduction/Adduction MCP [Kp,Kd,Pos,Vel,τff] (5 registers)
2. Flexion/Extension MCP [Kp,Kd,Pos,Vel,τff] (5 registers)
3. PIP [Kp,Kd,Pos,Vel,τff] (5 registers)
4. DIP [Kp,Kd,Pos,Vel,τff] (5 registers)

7.8 Thumb MIT Control

Used to control the 5-DOF thumb structure:

Address RangeParameter ArrayDescription
1550 ~ 15745-DOF Parameters25 registers ordered by logical joints J16~J20:
1. Rotation [Kp,Kd,Pos,Vel,τff] (5 registers)
2. MCP [Kp,Kd,Pos,Vel,τff] (5 registers)
3. IP [Kp,Kd,Pos,Vel,τff] (5 registers)
4. Abduction [Kp,Kd,Pos,Vel,τff] (5 registers)
5. Flexion [Kp,Kd,Pos,Vel,τff] (5 registers)

8. System Status

System status registers (address range 1800~1999) are read-only input registers.

AddressParameterUnitDescription
1800System Status CodeSee 8.1 System Status Code Definitions
1801Total CurrentmACurrent consumption of the hand
1802Total VoltageVSupply voltage of the hand
1803Total PowerWPower consumption of the hand
1804System TemperatureTemperature of the main control board

The device samples these system parameters internally at 5 Hz. Poll at no more than 5 Hz to avoid consuming bus bandwidth without obtaining newer data.

8.1 System Status Code Definitions

The status code register (1800) uses high and low bytes to indicate errors:

  • High 8 Bits (High Byte): Core fault flag
    • 0 = Normal
    • 1 = Fault
  • Low 8 Bits (Low Byte): Detailed exception categories
    • 0 = Normal
    • 1 = Communication failure
    • 2 = Uncalibrated
    • 3 = Temperature abnormal

9. Motor Feedback

Read input registers 2030~2999 to monitor motor state. The table below describes the 21-joint Revo3 Ultra layout. For other models, read only the joints declared by the active JointLayout.

Address RangeParameterUnitDescription
2030 ~ 2050Motor Velocityrpm × 100Current rotational speed of motors 0 ~ 20
2060 ~ 2080Motor Position° × 100Current angular position of motors 0 ~ 20
2090 ~ 2110Motor CurrentmACurrent drive current of motors 0 ~ 20
2120 ~ 2140Motor Fault CodeBit fieldSee 9.1 Motor Fault Code Definitions
2150 ~ 2170Motor TemperatureTemperature of motors 0 ~ 20 (internal or driver IC)

9.1 Motor Fault Code Definitions

The motor fault registers (2120~2140) use bitwise flags. Do not use reserved bits in application logic; preserve the raw value in logs and diagnostics.

BitDescription
0Over-current
1Over-voltage
2Under-voltage
3Over-temperature
4Current Spike
5 ~ 7Reserved
8Motor Stall
9 ~ 10Reserved
11Motor Running
12 ~ 15Reserved

10. Device Information

Device information registers (address range 3000~3999) are read-only.

Address RangeParameter NameFormat / Details
3020 ~ 3021Motor Online MaskRO, 32-bit bitmask; bits 0~20 map to motors 0~20
3030 ~ 3039Firmware VersionRO, Big-Endian ASCII string
3040 ~ 3049Hardware VersionRO, Big-Endian ASCII string
3050 ~ 3059Product SNRO, Big-Endian ASCII string
3060 ~ 3269Motor SNRO, Big-Endian ASCII string, 10 registers per motor SN (21 motors total)
3300 ~ 3320Motor Firmware VersionRO, binary version representation

10.1 Encoding Details

Versions & Serial Numbers (ASCII)

Strings are stored in Big-Endian byte order inside the registers. Each uint16_t register holds 2 characters:

  • High Byte: Holds the first character
  • Low Byte: Holds the second character

Each field uses 10 registers, supporting a maximum string length of 20 characters (including trailing null \0).

Decoding Example:

Register Array (Big-Endian uint16_t)Hexadecimal BytesDecoded ASCII String
0x534E, 0x3132, 0x3334, 0x3536, 0x3738, 0x3930, 0x3132, 0x3334, 0x350053 4E 31 32 33 34 35 36 37 38 39 30 31 32 33 34 35 00"SN123456789012345"

Motor Firmware Version

The motor firmware version is stored in a single uint16_t split into:

  • High Byte: Major version
  • Low Byte: Minor version

Parsing Format: Version = V[Major].[Minor]

  • E.g., read value 0x0105 represents version V1.5.

11. Touch Protocols

Touch modules integrated into the hand's primary communication link use the technical codes below. A device supports only the capabilities declared by its installed layout. Applications must not infer touch type or point count from the product name alone.

Technical CodeFunctional TypeRegister Area
Piezoresistive arrayPiezoresistive array touch module4000 series
High-density tactile arrayHigh-density tactile array module5000 series
Fingertip force/torqueFingertip force/torque touch module6500 series

Ultra VisionTouch's independent fingertip channels do not travel over the Modbus/CAN FD primary link and are not part of the register protocols below. Primary-link piezoresistive or high-density finger-pad and palm arrays on the same hand use the register protocols below after discovery confirms them.

11.1 Common Module IDs

The piezoresistive and high-density tactile arrays share the following 11 physical module IDs:

Module IDLocation
0Palm
1Thumb tip
2Thumb pad
3Index tip
4Index pad
5Middle tip
6Middle pad
7Ring tip
8Ring pad
9Pinky tip
10Pinky pad

A combined layout may use sparse module IDs. SDK applications must match data by TouchLayout.modules[*].module_id; do not assume that an array index always equals the module ID.

11.2 Piezoresistive Array Touch

Control Registers

AddressAccessFunction
4000 ~ 4010RWModule enable: 0 = Disabled, 1 = Enabled
4011WOZero-calibrate all modules; write any nonzero value
4012 ~ 4022WOZero-calibrate one module; write 1
4023RWRead mode: 0 = Point array, 1 = Compatibility regional-force summary
4024RWPoint value mode: 0 = ADC, 1 = Reserved, 2 = Force
4025WOAll regional forces: 2 = Tare, 3 = Restore factory baseline
4026 ~ 4036WOOne module's regional forces: 2 = Tare, 3 = Restore factory baseline

Mode 4023 = 1 is retained for compatibility with a limited number of delivered devices. New applications should use point-array mode and the SDK Touch API. Register 4024 value 1 is unused and must not be written.

Regional-force Input Registers

Each value is the sum of the calibrated pressure points in that region. The thumb pad currently exposes five values; register 4109 is reserved.

AddressContent
4100Palm resultant force
4101 ~ 4103Thumb-tip forces 1~3
4104 ~ 4108Thumb-pad forces 1~5
4109Reserved
4110 ~ 4112Index-tip forces 1~3
4113 ~ 4117Index-pad forces 1~5
4118 ~ 4120Middle-tip forces 1~3
4121 ~ 4125Middle-pad forces 1~5
4126 ~ 4128Ring-tip forces 1~3
4129 ~ 4133Ring-pad forces 1~5
4134 ~ 4136Pinky-tip forces 1~3
4137 ~ 4141Pinky-pad forces 1~5

Point-array Input Registers

ModuleAddress RangePoints
Palm4200 ~ 423536
Thumb tip4250 ~ 428031
Thumb pad4290 ~ 434657
Index tip4350 ~ 437021
Index pad4400 ~ 445152
Middle tip4460 ~ 448021
Middle pad4500 ~ 455152
Ring tip4560 ~ 458021
Ring pad4600 ~ 465152
Pinky tip4660 ~ 468021
Pinky pad4700 ~ 475152

11.3 High-density Tactile Array

AddressType / AccessFunction
5003 ~ 5178Input / ROSerial numbers for 11 modules; 16 registers and 32 Bytes per module, high byte first
5179Holding / WORestart all modules; write 1
5180 ~ 5190Holding / WORestart one module; write 1
5191 ~ 5201Input / ROActual point count for each module
5202Holding / RWOutput mode for all modules: 0 = ADC, 1 = Force
5203 ~ 5213Holding / RWOutput mode for one module
5214Holding / WOTare command for all modules: 1 = Tare, 2 = Cancel/restore default baseline
5215 ~ 5225Holding / WOTare command for one module
5226Holding / ROGlobal tare status: 0 = Not tared, 1 = Tared, 2 = Busy or failed
5227 ~ 5237Holding / ROTare status for one module
5240 ~ 5839Input / ROPoint-array data buffers
5900 ~ 5910Holding / RWModule enable: 0 = Disabled, 1 = Enabled

Each point-data register contains two uint8 values, high byte first. ADC values range from 0~255. In force mode, each raw unit represents 10 mN. Read the active point counts from 5191~5201; never substitute buffer capacity for the active count.

ModuleData StartBuffer Capacity (points)
Palm5240200
Thumb tip534080
Thumb pad5380120
Index tip544080
Index pad5480120
Middle tip554080
Middle pad5580120
Ring tip564080
Ring pad5680120
Pinky tip574080
Pinky pad5780120

Current firmware reads serial numbers, point counts, and point-array data with function code 0x04. Some earlier firmware exposes a holding-register compatibility mapping. Use SDK auto-detection for legacy devices instead of hard-coding a guessed function code.

11.4 Fingertip Force/Torque Touch

This layout contains five fingertip modules ordered as Thumb, Index, Middle, Ring, and Pinky.

AddressAccessFunction
6500 ~ 6504RWModule enable: 0 = Disabled, 1 = Enabled
6510 ~ 6514WOForce/torque zeroing; write 1
6520 ~ 6709ROFive module blocks, each containing 38 input registers

The module blocks start at 6520, 6558, 6596, 6634, and 6672. Each block uses the following offsets:

Block OffsetData TypeContent
0uint16Module state: 0 = Warming up, 1 = Ready, 2 = Offline
1uint16Sensor state: 0 = Normal, nonzero = Fault
2 ~ 115 × float32Fx, Fy, Fz, Mx, My, with the high 16-bit word first
12 ~ 13float32Scalar resultant force Fn; it is not Fz
14 ~ 3748 × uint8Film points; odd-numbered point in the high byte, even-numbered point in the low byte

The protocol expresses Fx, Fy, and Fz in N and Mx, My in N·m. The SDK exposes force in mN. Applications should use force, torque, and point-array values only when both module and sensor state are normal.

11.5 SDK Guidance

The SDK normalizes the different touch protocols into TouchLayout and TouchFrame. Read module ID, point count, region, and signal capabilities from the layout, and use each frame's TouchSampleState to determine whether its data is valid. Stop parsing an unknown layout; never apply another device's fixed point order or geometry mapping.


12. Joint ID Definitions

Revo3 Ultra has 21 active joints. The diagram below maps each joint ID to its physical location:

Revo3 Ultra Joint ID DefinitionsRevo3 Ultra joint ID layout for 21 active joints
Help