Modbus function and exception codes

Look up any public Modbus function code or exception code, or paste an exception response such as 83 02 to see which request failed and why.

Modbus and serial Updated Free, no sign-up

What do you have?

Examples

A function code (16 or 0x10), an exception response off the wire, or words from a name

Exception 0x03

Illegal Data Value

Request that failed
0x10 Write Multiple Registers
Meaning
The request data structure contains a value the server cannot accept; it does not describe the application value stored in a register.
Bytes read
90 03

The first byte is the function code plus 0x80, which marks an exception; the second is the exception code.

How it’s calculated

Exception response function code = request function code + 0x80

Response 90 03 means the Write Multiple Registers request (0x10) failed with exception 0x03, Illegal Data Value.

Tip: No reply at all is not an exception. Check wiring, the unit ID, baud rate, parity and termination before the register map.

How to read a Modbus exception response

When a Modbus device receives a request it cannot carry out, it answers with an exception response: the function code with its top bit set (the code plus 0x80), then a one-byte exception code. 83 02 means a Read Holding Registers request (0x03) failed with exception 02, Illegal Data Address. Paste the response bytes into the box above to decode them.

The function byte

function in the response = request function + 0x80

A normal reply repeats the request’s function code. An exception sets the top bit, so 0x03 becomes 0x83 and 0x10 becomes 0x90. Subtract 0x80 to find the request that failed.

The exception code

01 function · 02 address · 03 value · 04 device failure

01 Illegal Function: the device does not support the request. 02 Illegal Data Address: the address, or the address plus the count, is outside what it holds. 03 Illegal Data Value: a value in the request is not allowed. 04 Server Device Failure: the device failed while carrying it out.

Function codes in decimal and hex

FC16 = 16 decimal = 0x10

Manuals quote function codes both ways. The box above reads a bare number as decimal when that names a function (16 is Write Multiple Registers) and shows the hexadecimal reading beside it; write 0x16 to mean hexadecimal.

No reply at all is not an exception. A timeout points at the wiring, the unit ID, the baud rate and parity, termination, or a frame the device threw away for a bad CRC. Only a device that understood the frame can send an exception.

Modbus exception code examples

Response 83 02 from a meter

Subtract 0x80 from 0x83 to get 0x03, Read Holding Registers. Exception 02 is Illegal Data Address: the registers asked for do not exist in the device. The usual cause is an off-by-one address from a 40001-style reference, or a request that runs past the end of a block; the Modbus address converter settles the first.

Exception 0x02 Illegal Data Address Open in the calculator

Response 90 03 after a write

0x90 − 0x80 = 0x10, Write Multiple Registers, and 03 is Illegal Data Value. The device received the frame but refused a value in it: a setpoint outside its range, a register count that does not match the byte count, or a write to a read-only block.

Exception 0x03 Illegal Data Value Open in the calculator

What is function 16?

In decimal, function 16 is Write Multiple Registers, sent on the wire as 0x10. Read as hexadecimal, 0x16 would be Mask Write Register, a different request. When a manual says “FC16” it means decimal.

Function 16 (0x10) Write Multiple Registers Open in the calculator

Modbus function codes and their exception responses

The common public function codes in decimal and hexadecimal, and the first byte a device sends back if the request fails.

FunctionNameHexException response
1Read Coils0x010x81
2Read Discrete Inputs0x020x82
3Read Holding Registers0x030x83
4Read Input Registers0x040x84
5Write Single Coil0x050x85
6Write Single Register0x060x86
15Write Multiple Coils0x0F0x8F
16Write Multiple Registers0x100x90
22Mask Write Register0x160x96
23Read/Write Multiple Registers0x170x97
43Encapsulated Interface Transport0x2B0xAB

Download this table (CSV)

Reference tables

Public function codes

Defined public functions in V1.1b3. A listed function is not proof that a particular device implements it.

CodeFunctionData accessProtocol request limitTransport note
0x01Read CoilsRead coils · bits1–2,000 contiguous coilsApplication protocol
0x02Read Discrete InputsRead discrete inputs · bits1–2,000 contiguous inputsApplication protocol
0x03Read Holding RegistersRead holding registers · 16-bit words1–125 contiguous registersApplication protocol
0x04Read Input RegistersRead input registers · 16-bit words1–125 contiguous registersApplication protocol
0x05Write Single CoilWrite one coil · bitExactly one coilApplication protocol
0x06Write Single RegisterWrite one holding register · 16-bit wordExactly one registerApplication protocol
0x07Read Exception StatusRead eight implementation-defined status outputsNo request dataSerial line only
0x08DiagnosticsCommunication diagnostics by subfunctionSubfunction-specificSerial line only
0x0BGet Comm Event CounterRead communications status and event countNo request dataSerial line only
0x0CGet Comm Event LogRead communications status, counters and event bytesNo request dataSerial line only
0x0FWrite Multiple CoilsWrite contiguous coils · bits1–1,968 contiguous coilsApplication protocol
0x10Write Multiple RegistersWrite contiguous holding registers · 16-bit words1–123 contiguous registersApplication protocol
0x11Report Server IDRead device-specific identity and run statusNo request dataSerial line only
0x14Read File RecordRead one or more file-record groupsRequest byte count 7–245Application protocol
0x15Write File RecordWrite one or more file-record groupsRequest byte count 9–251Application protocol
0x16Mask Write RegisterModify bits in one holding registerExactly one registerApplication protocol
0x17Read/Write Multiple RegistersWrite holding registers, then read holding registersRead 1–125; write 1–121 registersApplication protocol
0x18Read FIFO QueueRead FIFO count and value registersReturned FIFO count no more than 31Application protocol
0x2BEncapsulated Interface TransportDispatch an MEI-defined interfacePublished MEI types 0x0D and 0x0EApplication protocol

Source: MODBUS Application Protocol Specification, V1.1b3

Primary data objects

The four primary Modbus data tables. Device memory mapping and whether tables overlay are implementation-specific.

ObjectElementProtocol accessCore public functions
CoilsSingle bitRead–write0x01 read · 0x05/0x0F write
Discrete InputsSingle bitRead-only0x02 read
Input Registers16-bit wordRead-only0x04 read
Holding Registers16-bit wordRead–write0x03 read · 0x06/0x10/0x16/0x17 write

Source: MODBUS Application Protocol Specification, V1.1b3

Exception codes

Exception codes returned in a Modbus exception response. A timeout or discarded CRC/parity error is not itself one of these exception responses.

CodeExceptionProtocol meaning
0x01Illegal FunctionThe requested function is not allowable for this server or its current state.
0x02Illegal Data AddressThe starting address, requested span or their combination is not allowable for the server.
0x03Illegal Data ValueThe request data structure contains a value the server cannot accept; it does not describe the application value stored in a register.
0x04Server Device FailureAn unrecoverable error occurred while the server attempted the requested action.
0x05AcknowledgeThe server accepted a specialised programming request but needs more time to complete it.
0x06Server Device BusyThe server is busy with a long-duration programming command; the client may retry later.
0x08Memory Parity ErrorA file-record consistency check failed while using function 0x14 or 0x15 with reference type 0x06.
0x0AGateway Path UnavailableA gateway could not allocate an internal path from its input port to the requested output path.
0x0BGateway Target Device Failed to RespondA gateway did not obtain a response from the target device.

Source: MODBUS Application Protocol Specification, V1.1b3

Questions about Modbus exception codes

What does Modbus exception 02 mean?

Illegal Data Address. The device does not hold the address asked for, or the address plus the number of registers runs past what it holds. Check the address convention and the length of the read.

What does Modbus exception 01 mean?

Illegal Function. The device does not support that function code, or not in its current state. Many meters support only a few functions, often 03, 04 and 16.

Why do I get a timeout instead of an exception?

The device never understood the request: wrong unit ID, baud rate or parity, reversed A and B wires, missing termination, or a CRC error. Exceptions only come from a device that read the frame correctly. The RS-485 termination and bias checker covers the wiring side.

What are exceptions 0A and 0B?

Gateway exceptions. 0A, Gateway Path Unavailable, means the gateway could not route the request; 0B, Gateway Target Device Failed to Respond, means the device behind it did not answer. Both point past the gateway, to the serial side.

Limits of this result

  • A public function code is not proof that a particular server implements it; confirm the current device register map and firmware documentation.
  • Function code alone does not establish register meaning, scaling, signedness, byte/word order, address convention or whether a write is safe.
  • Functions marked serial-line only are not general Modbus TCP services. Gateway behaviour can add further restrictions.
  • Treat no response separately from an exception response. Cabling, timing, unit ID, CRC/parity, routing and device availability still require diagnosis.

Read Modbus devices on the Gateway

A ZMB reads and writes Modbus RTU devices locally and sends the data to the Gateway over the wireless mesh, so a meter can be integrated without a data cable back to the panel.

Related guides

Sources

  1. MODBUS Application Protocol Specification V1.1b3 (opens in a new tab) (PDF) Modbus Organization, 2012-04-26
  2. Specifications and Implementation Guides (opens in a new tab) Modbus Organization, accessed 2026-09-14