Modbus address converter

Translate a Modbus address the way a device manual writes it (40001, 400001, 1-based or 0-based) into every other convention, including the offset on the wire.

Modbus and serial Updated Free, no sign-up

300015-digit reference
3000016-digit reference
11-based number
00-based, on the wire

Input register, offset 0 (0x0000).

The registers either side

0-based offsetas written
  1. 030001
  2. 130002one above
  3. 230003
  4. 330004
  5. 430005
  6. 530006
  7. 630007

Reading the register next door? The manual and the software disagree on counting from 0 or 1: try the one either side.

The four tables

  • 0xCoilssingle bitsread 01, write 05 and 15
  • 1xDiscrete inputssingle bits, read-onlyread 02
  • 3xInput registers16-bit words, read-onlyread 04
  • 4xHolding registers16-bit wordsread 03, write 06 and 16

The read request for this one

  1. 04function
  2. 00address, high
  3. 00address, low
  4. 00quantity, high
  5. 01quantity, low

The digit at the front of a reference (3) is never sent: function 04 chooses the table, and 0x0000 is the address.

Finish the RTU frame for unit 1, with its CRC
Address from the manual
Written as
Register table
Table

Offset on the wire, 0-based

0

Offset in hexadecimal
0x0000
1-based number
1
5-digit reference
30001
6-digit reference
300001
Read with function code
04

Input register, from the 3 that starts the reference. The function code chooses the table; the digit is never sent.

How it’s calculated
  1. Offset = address − 30001=30001 − 30001=0
  2. Hex = offset in base 16=0=0x0000

Input register 30001 is address 0 (0x0000) in the Modbus request.

Tip: If every value reads as the register next door, the software and the manual disagree about 0-based and 1-based numbering. Shift by one.

How to convert a Modbus reference to the register address

Manuals write Modbus addresses in several ways: 40001, 400001, register 1 or address 0 can all mean the same holding register. What a Modbus request carries is the 0-based address, 0 to 65535, and the function code picks the table. To convert a reference like 40001, subtract the first reference of its table: 40001 − 40001 = 0. Type a 5- or 6-digit reference exactly as the manual prints it and the calculator reads the table from its first digit; a 1-based or 0-based number needs the table chosen.

5-digit reference (40001)

address = reference − 40001

The first digit names the table: 0 for coils, 1 for discrete inputs, 3 for input registers and 4 for holding registers. Subtract 00001, 10001, 30001 or 40001. This style reaches only 9,999 items per table.

6-digit reference (400001)

address = reference − 400001

The same idea with room for 65,536 items per table. Subtract 000001, 100001, 300001 or 400001.

1-based register number

address = number − 1

Some maps number registers from 1 without a table digit. Register 1 is address 0.

0-based address

address = number

Maps written for programmers often give the address exactly as it goes in the request, frequently in hexadecimal.

The table is chosen by the function code, not by the address: 01 reads coils, 02 discrete inputs, 03 holding registers and 04 input registers. The 4 in 40001 tells you to use function 03; it is never sent.

Modbus address examples

A meter voltage at 30001

A meter manual lists phase voltage at 30001. That is the first input register: read it with function 04 at address 0.

Offset on the wire, 0-based 0 Open in the calculator

An off-by-one reading from 40108

The map gives a setpoint at 40108, so the request uses function 03 at address 107 (0x006B). Entering 108 reads the next register instead, a mistake that often returns a plausible but wrong value, so check one register you can confirm first.

Offset on the wire, 0-based 107 Open in the calculator

A 6-digit reference beyond 9999

Large maps use 6-digit references because the 5-digit style stops at 49999. Reference 412001 is holding register address 12000 (0x2EE0).

Offset on the wire, 0-based 12000 Open in the calculator

Modbus reference ranges by table

The first and last 5-digit references of each table and where the 6-digit style begins. Every range starts at address 0 in the request.

TableFirst 5-digitLast 5-digitFirst 6-digit
Coils0000109999000001
Discrete inputs1000119999100001
Input registers3000139999300001
Holding registers4000149999400001

Download this table (CSV)

Questions about Modbus register addresses

Does 40001 mean register 40001?

No. It means the first holding register, which is address 0 in the request. The leading 4 names the table and the rest counts from 1.

Why is my Modbus reading one register out?

The usual cause is a mix of 0-based and 1-based numbering: the map counts from 1 and the software from 0, or the other way round. If a reading looks like its neighbour’s value, move the address by one and compare.

Which function code reads holding registers?

Function 03 reads holding registers and 04 reads input registers. 06 writes one holding register and 16 (0x10) writes several.

What is the highest Modbus address?

65535 (0xFFFF) in each table, because the address field in the request is 16 bits. Five-digit references cannot reach past 9999 in a table, which is why 6-digit references exist.

Limits of this result

  • Confirm the source data, device datasheet and installation conditions before relying on the result.

Read Modbus devices on the Gateway

A ZMB connects an RS-485 Modbus device to the wireless network. Discrete inputs and input registers are read-only; coils and holding registers may be writable where the device allows. The Gateway can also read Modbus devices directly.

Related guides

Sources

  1. MODBUS Application Protocol Specification V1.1b3 (opens in a new tab) (PDF) Modbus Organization, 2012-04-26
  2. An Introduction to Modbus (opens in a new tab) Modbus Organization, accessed 2026-09-14