Keyence KV Integration Guide
Talk directly to Keyence KV PLCs with MaestroHub's Keyence connector, which speaks Host Link (Keyence's "upper link" protocol): ASCII commands over TCP, served by the PLC's built-in Ethernet port or a KV-EP21V / KV-NC1EP unit. This guide covers connection setup, device addressing, the data types, authoring read and write functions, the tag map, and the matching pipeline nodes.
Overview
The Keyence connector provides:
- Relays and data memory: read and write
R,B,MR,LR,CR,VB(bits) andDM,EM,FM,ZF,W,TM,Z,CM,VM(words) - Timers and counters: contacts (
T,C), current and set values (TC,TS,CC,CS), high-speed counters (CTH,CTC) and the digital trimmer (AT) - Typed values:
BIT,WORD,INT,DWORD,DINT,REAL,LREALorSTRING(UTF-8, Shift-JIS or Windows-1251); relays read 16 at a time as words, and a bit inside a data-memory word asBIT - Block reads: many named points in the fewest requests, within the PLC's per-request count limits
- Safe bit writes: a single relay is set or reset on its own (
ST/RS); a bit inside a data-memory word is written by reading the word and writing it back - Symbolic tag mapping: friendly names for device addresses, importable from CSV or JSON
KV-8000, KV-7500/7300, KV-5500/5000/3000 and KV-X through their built-in Ethernet port or a KV-EP21V unit, and the KV Nano series through a KV-NC1EP unit. The connector asks the PLC for its model when it connects and applies that series' count limits (1000 words per request on KV, 256 on a KV Nano).
Host Link over TCP only. UDP, RUN/PROGRAM mode changes, clock writes, monitor registration, device comments and unit buffer access are not supported.
Connection Configuration
Creating a Keyence Connection
Navigate to Connections → New Connection → Keyence KV and fill in the form. It has five tabs: Connection, Tag Map, Functions, Scaling and Health. Functions, Scaling and Health unlock after the connection is saved.
1. Profile Information
| Field | Default | Description |
|---|---|---|
| Profile Name | — | A descriptive name for this connection profile (required, max 100 characters). Must be unique across all connections. |
| Description | — | Optional description for this connection |
| Labels | — | Key-value pairs to categorize and organize the connection (max 10 labels) |
2. Host Link Settings
| Field | Default | Description |
|---|---|---|
| Address | — | PLC host name or IP address (required) |
| Port | 8501 | Host Link TCP port. 8501 is the KV default; it is set in KV STUDIO's unit settings. |
| Connection Timeout | 5s | Maximum time to open the TCP connection and read the PLC model |
| String Encoding | utf-8 | How STRING values are stored in the PLC: utf-8, shift-jis (Japanese text written by KV STUDIO) or windows-1251 (Cyrillic). |
Each function has its own Timeout (default 30m) that bounds one request. The connector sends each request once: if the PLC does not answer in time, the connection is closed and reopened rather than reused, because Host Link replies carry no request number and a late reply could otherwise answer the next request.
3. Tag Map
The Tag Map tab attaches an optional symbolic tag list; see Symbolic Tag Map. Every operation can always use a raw device address.
Testing the Connection
Click Test Connection at the bottom of the form. The probe opens the connection and asks the PLC for its model (?K), then reports the latency. A wrong address, port or a device that is not a KV PLC fails here.
Device Addressing
A device address is a device code followed by a number, e.g. DM100, MR1203, W1FF.
- Relays (
R,MR,LR,CR) are a channel followed by a two-digit bit00–15:MR1203is channel 12, bit 03, andR10015is channel 100, bit 15. The bit afterR10015isR10100. A bare number is a relayR(100isR100). - Link relays, link registers and work relays (
B,W,VB) are numbered in hexadecimal:W1FFis register 511. - Everything else is decimal.
- A bit inside a data-memory word is the word, a dot, and the bit:
DM100.05(two digits00–15) orDM100.A(one hexadecimal digit0–F). It is read asBIT. Writing one sets or resets just that bit. Host Link has no command for a bit inside a word, so MaestroHub reads the word, changes the one bit and writes the word back, with none of its own requests in between, and skips the write when the bit already has the value. This is what the legacy driver did. A change the PLC program makes to the other bits of that word between the read and the write can still be overwritten, so keep bits the PLC writes in a different word, or use a relay (MR,LR) for control bits. - Relays as words: a relay address read as
WORD,INT,DWORD,DINT,REALorLREALtakes 16 relays per word starting at that address, lowest relay in bit 0:MR1000asWORDisMR1000–MR1015. Written the same way, every relay in the word is set from the value.
Supported Devices
| Code | Device | Read as | Writable |
|---|---|---|---|
R | Relay | BIT, or 16 at a time as a word type | Yes |
B | Link relay (hex) | BIT, or 16 at a time as a word type | Yes |
MR | Internal auxiliary relay | BIT, or 16 at a time as a word type | Yes |
LR | Latch relay | BIT, or 16 at a time as a word type | Yes |
CR | Control relay | BIT, or 16 at a time as a word type | Yes |
VB | Work relay (hex) | BIT, or 16 at a time as a word type | Yes |
DM | Data memory | word types | Yes |
EM | Extended data memory | word types | Yes |
FM | File register | word types | Yes |
ZF | File register | word types | Yes |
W | Link register (hex) | word types | Yes |
TM | Temporary data memory | word types | Yes |
CM | Control memory | word types | Yes |
VM | Work memory | word types | Yes |
Z | Index register (32-bit) | DWORD, DINT, REAL; WORD, INT for the lower 16 bits | Yes |
T | Timer | BIT for the contact (set / reset); a number type for the current value (as TC) | Yes |
TC / TS | Timer current / set value | DWORD, DINT, REAL; WORD, INT for the lower 16 bits | Yes |
C | Counter | BIT for the contact (set / reset); a number type for the current value (as CC) | Yes |
CC / CS | Counter current / set value | DWORD, DINT, REAL; WORD, INT for the lower 16 bits | Yes |
CTH | High-speed counter | 32-bit types as TC | Where the PLC allows it |
CTC | High-speed counter comparator | 32-bit types as TC; BIT resets its contact (write false; the PLC allows reset only) | Yes |
AT | Digital trimmer | 32-bit types as TC | No |
The PLC decides which numbers exist on your model: an address outside its range fails with E0 (device number out of range).
Supported Data Types
| Data Type | Words | Value | Example |
|---|---|---|---|
BIT | — | boolean | true |
WORD | 1 | unsigned 16-bit (0–65,535) | 1234 |
INT | 1 | signed 16-bit (−32,768 to 32,767) | -100 |
DWORD | 2 | unsigned 32-bit | 70000 |
DINT | 2 | signed 32-bit | -70000 |
REAL | 2 | 32-bit float | 72.5 |
LREAL | 4 | 64-bit float | 3.141592653589793 |
STRING | ⌈length / 2⌉ | text | LOT-42 |
Multi-word values are stored low word first, as the KV stores them. On Z, TC, TS, CC, CS, AT, CTH and CTC each device number already holds one 32-bit value, so DWORD, DINT and REAL read one device each, and WORD or INT read its lower 16 bits.
A STRING packs two bytes per word with the first byte in the high byte, which is how KV STUDIO writes text. Its String Length is in bytes: one per ASCII character, two per Shift-JIS Japanese character. Text is NUL-padded on write and ends at the first NUL on read. Text longer than the length is refused, not cut.
Symbolic Tag Map
The tag map lets functions use a friendly name (Press.Count) instead of an address (DM100). Each tag maps a name to a device, a data type and, for strings, a length:
| Field | Required | Description |
|---|---|---|
name | Yes | Tag name, unique within the connection |
device | Yes | Device address, e.g. DM100 or MR1203 |
dataType | Yes | BIT, WORD, INT, DWORD, DINT, REAL, LREAL or STRING |
length | No | String length in bytes, for STRING tags |
Saving refuses a duplicate name, an address that does not parse, or a data type the device cannot hold (DM100 as BIT).
Importing tags (CSV or JSON)
Paste tags into the Import box and click Import Tags.
name,device,dataType,length
Press.Count,DM100,DINT
Press.Alarm,MR1203,BIT
Press.Lot,DM300,STRING,10
[
{ "name": "Press.Count", "device": "DM100", "dataType": "DINT" },
{ "name": "Press.Alarm", "device": "MR1203", "dataType": "BIT" }
]
Function Builder
Creating Keyence Functions
After the connection is saved:
- Open the connection and go to the Functions tab
- Click New Function and choose Read Device, Read Block (Multi) or Write Device
- Fill the Basic fields (name, description, labels) and the Configuration fields
- Use Test Function to run it against the live PLC before saving
Read Device (keyence.read.device)
Read one typed value from a device or tag, or Count consecutive values as a list.
| Field | Required | Default | Description |
|---|---|---|---|
| Device / Tag | Yes | — | A device address (DM100, MR1203, T5, DM100.05) or a tag name |
| Data Type | No | WORD | How to interpret the value |
| Count | No | 1 | Consecutive values to read (1–1000). More than 1 returns a list. Ignored for STRING. |
| String Length | No | 1 | Bytes, for STRING |
| Timeout | No | 30m | Bound on this operation |
A read larger than one request carries is split into several requests.
Read Block (Multi) (keyence.read.block)
Read many named points. Each point has a name (the key in the result; names must be unique), a device (address or tag), a data type, and for strings a length. Neighbouring addresses of the same device type share one request, and no request exceeds the PLC's count limit. If any point is invalid, nothing is sent.
Write Device (keyence.write.device)
Write one typed value, or a JSON list such as [1, 2, 3] to consecutive devices in one request.
| Field | Required | Default | Description |
|---|---|---|---|
| Device / Tag | Yes | — | A writable device address or a tag name |
| Data Type | No | WORD | How to encode the value |
| Value | Yes | — | The value, or a JSON list. Supports ((paramName)) templates. |
| String Length | No | 1 | Bytes, for STRING |
| Timeout | No | 30m | Bound on this operation |
- A single relay
BITis set or reset on its own (ST/RS); a list of bits is written in one request. A bit inside a word (DM100.05) is read, changed and written back as its word. - The whole value is checked before anything is sent. A value the type cannot hold, a non-whole number for an integer type, or text longer than the string length is refused.
- A write that would need more than one request (over 1000 words on KV, 256 on a KV Nano) is refused, so a list is never half written.
- A write is sent once. If the PLC does not answer in time, the result says so; MaestroHub does not repeat the write, because the PLC may already have applied it.
Using Parameters
The Value field supports ((parameterName)) placeholders; they appear in the Function Parameters block, where you set each one's type, whether it is required, and a default. For example, Device DM200, Data Type REAL, Value ((setpoint)) writes the node's setpoint parameter to DM200.
Testing Functions
Click Test Function on the function form, enter values for any ((parameters)), and click Execute Test. The dialog shows the decoded value or the PLC's error reply. You do not need to save the function first. Testing a Write Device function writes to the PLC.
Pipeline Integration
Each operation has its own node: Keyence Read (connected.keyence.read.device), Keyence Block Read (connected.keyence.read.block) and Keyence Write (connected.keyence.write.device), plus the Keyence Read Group (connected.keyence.readgroup) for several reads in one node. To poll a PLC, drive the reads from a Schedule trigger.
See Keyence KV Nodes for the node reference.
Common Use Cases
Line monitoring to a historian or the UNS
A Read Block of the line's counts, speeds and alarm relays on a Schedule trigger, routed to the Unified Namespace or a historian.
Setpoints and recipes
Parameterized Write Device functions (Value: ((setpoint))) fed from an MES or an operator form, with a Condition node checking the range first.
Machine control relays
Set or reset MR relays to acknowledge alarms or start sequences. Only the addressed bit changes.
Troubleshooting
Connection Issues
| Symptom | Possible cause | Solution |
|---|---|---|
| Test Connection times out | Nothing listening on that address and port, or a firewall | Check the PLC's IP address and Host Link port (8501 by default) in KV STUDIO, and that the port is reachable from MaestroHub. |
the PLC refused the request (E1 …) on Test Connection | The port answers but is not a KV Host Link server | Point the connection at the PLC's Host Link port. |
| Connections drop when several clients poll | The PLC serves a small number of Host Link connections | Use one MaestroHub connection per PLC and group reads into Read Block or Read Group nodes. |
Read / Write Issues
| Symptom | Possible cause | Solution |
|---|---|---|
E0: device number out of range | The address does not exist on this model, or the read runs past its end | Check the device range for your model in the KV manual. |
E2: no program, or the RUN/PROG switch is at PROG | The PLC is in PROGRAM mode | Switch the PLC to RUN. The failure is transient, so a retry succeeds once it is running. |
E4: write-protected | The device is write-protected in the PLC | Remove the protection in KV STUDIO, or write another device. |
DM0 (Data memory) is a word device: use WORD … | BIT chosen on a data-memory device | Read relays as BIT; read data memory as a word type. |
A W or B address reads the wrong value | Hex numbering: W20 is register 32 | Write the address in hexadecimal. |
MR1216 … bit 16 is not 00-15 | The last two digits of a relay are the bit | MR1216 does not exist; the bit after MR1215 is MR1300. |
A STRING reads only two characters | String Length left at 1 | Set the length in bytes on both the write and the read. |
| Japanese or Cyrillic text reads as garbage | Wrong String Encoding | Set the connection's String Encoding to shift-jis or windows-1251. |