Skip to main content
Version: 3.0 (next)

Keyence KV Keyence KV Integration Guide

Talk directly to Keyence KV PLCs with MaestroHub's Keyence connector, which speaks Host Link (Keyence's "upper link" protocol): ASCII commands over TCP, served by the PLC's built-in Ethernet port or a KV-EP21V / KV-NC1EP unit. This guide covers connection setup, device addressing, the data types, authoring read and write functions, the tag map, and the matching pipeline nodes.

Overview​

The Keyence connector provides:

  • Relays and data memory: read and write R, B, MR, LR, CR, VB (bits) and DM, EM, FM, ZF, W, TM, Z, CM, VM (words)
  • Timers and counters: contacts (T, C), current and set values (TC, TS, CC, CS), high-speed counters (CTH, CTC) and the digital trimmer (AT)
  • Typed values: BIT, WORD, INT, DWORD, DINT, REAL, LREAL or STRING (UTF-8, Shift-JIS or Windows-1251); relays read 16 at a time as words, and a bit inside a data-memory word as BIT
  • Block reads: many named points in the fewest requests, within the PLC's per-request count limits
  • Safe bit writes: a single relay is set or reset on its own (ST / RS); a bit inside a data-memory word is written by reading the word and writing it back
  • Symbolic tag mapping: friendly names for device addresses, importable from CSV or JSON
Supported PLCs

KV-8000, KV-7500/7300, KV-5500/5000/3000 and KV-X through their built-in Ethernet port or a KV-EP21V unit, and the KV Nano series through a KV-NC1EP unit. The connector asks the PLC for its model when it connects and applies that series' count limits (1000 words per request on KV, 256 on a KV Nano).

Host Link over TCP only. UDP, RUN/PROGRAM mode changes, clock writes, monitor registration, device comments and unit buffer access are not supported.

Connection Configuration​

Creating a Keyence Connection​

Navigate to Connections → New Connection → Keyence KV and fill in the form. It has five tabs: Connection, Tag Map, Functions, Scaling and Health. Functions, Scaling and Health unlock after the connection is saved.

1. Profile Information​

FieldDefaultDescription
Profile Name—A descriptive name for this connection profile (required, max 100 characters). Must be unique across all connections.
Description—Optional description for this connection
Labels—Key-value pairs to categorize and organize the connection (max 10 labels)
FieldDefaultDescription
Address—PLC host name or IP address (required)
Port8501Host Link TCP port. 8501 is the KV default; it is set in KV STUDIO's unit settings.
Connection Timeout5sMaximum time to open the TCP connection and read the PLC model
String Encodingutf-8How STRING values are stored in the PLC: utf-8, shift-jis (Japanese text written by KV STUDIO) or windows-1251 (Cyrillic).

Each function has its own Timeout (default 30m) that bounds one request. The connector sends each request once: if the PLC does not answer in time, the connection is closed and reopened rather than reused, because Host Link replies carry no request number and a late reply could otherwise answer the next request.

3. Tag Map​

The Tag Map tab attaches an optional symbolic tag list; see Symbolic Tag Map. Every operation can always use a raw device address.

Testing the Connection​

Click Test Connection at the bottom of the form. The probe opens the connection and asks the PLC for its model (?K), then reports the latency. A wrong address, port or a device that is not a KV PLC fails here.

Device Addressing​

A device address is a device code followed by a number, e.g. DM100, MR1203, W1FF.

  • Relays (R, MR, LR, CR) are a channel followed by a two-digit bit 00–15: MR1203 is channel 12, bit 03, and R10015 is channel 100, bit 15. The bit after R10015 is R10100. A bare number is a relay R (100 is R100).
  • Link relays, link registers and work relays (B, W, VB) are numbered in hexadecimal: W1FF is register 511.
  • Everything else is decimal.
  • A bit inside a data-memory word is the word, a dot, and the bit: DM100.05 (two digits 00–15) or DM100.A (one hexadecimal digit 0–F). It is read as BIT. Writing one sets or resets just that bit. Host Link has no command for a bit inside a word, so MaestroHub reads the word, changes the one bit and writes the word back, with none of its own requests in between, and skips the write when the bit already has the value. This is what the legacy driver did. A change the PLC program makes to the other bits of that word between the read and the write can still be overwritten, so keep bits the PLC writes in a different word, or use a relay (MR, LR) for control bits.
  • Relays as words: a relay address read as WORD, INT, DWORD, DINT, REAL or LREAL takes 16 relays per word starting at that address, lowest relay in bit 0: MR1000 as WORD is MR1000–MR1015. Written the same way, every relay in the word is set from the value.

Supported Devices​

CodeDeviceRead asWritable
RRelayBIT, or 16 at a time as a word typeYes
BLink relay (hex)BIT, or 16 at a time as a word typeYes
MRInternal auxiliary relayBIT, or 16 at a time as a word typeYes
LRLatch relayBIT, or 16 at a time as a word typeYes
CRControl relayBIT, or 16 at a time as a word typeYes
VBWork relay (hex)BIT, or 16 at a time as a word typeYes
DMData memoryword typesYes
EMExtended data memoryword typesYes
FMFile registerword typesYes
ZFFile registerword typesYes
WLink register (hex)word typesYes
TMTemporary data memoryword typesYes
CMControl memoryword typesYes
VMWork memoryword typesYes
ZIndex register (32-bit)DWORD, DINT, REAL; WORD, INT for the lower 16 bitsYes
TTimerBIT for the contact (set / reset); a number type for the current value (as TC)Yes
TC / TSTimer current / set valueDWORD, DINT, REAL; WORD, INT for the lower 16 bitsYes
CCounterBIT for the contact (set / reset); a number type for the current value (as CC)Yes
CC / CSCounter current / set valueDWORD, DINT, REAL; WORD, INT for the lower 16 bitsYes
CTHHigh-speed counter32-bit types as TCWhere the PLC allows it
CTCHigh-speed counter comparator32-bit types as TC; BIT resets its contact (write false; the PLC allows reset only)Yes
ATDigital trimmer32-bit types as TCNo

The PLC decides which numbers exist on your model: an address outside its range fails with E0 (device number out of range).

Supported Data Types​

Data TypeWordsValueExample
BIT—booleantrue
WORD1unsigned 16-bit (0–65,535)1234
INT1signed 16-bit (−32,768 to 32,767)-100
DWORD2unsigned 32-bit70000
DINT2signed 32-bit-70000
REAL232-bit float72.5
LREAL464-bit float3.141592653589793
STRING⌈length / 2⌉textLOT-42

Multi-word values are stored low word first, as the KV stores them. On Z, TC, TS, CC, CS, AT, CTH and CTC each device number already holds one 32-bit value, so DWORD, DINT and REAL read one device each, and WORD or INT read its lower 16 bits.

A STRING packs two bytes per word with the first byte in the high byte, which is how KV STUDIO writes text. Its String Length is in bytes: one per ASCII character, two per Shift-JIS Japanese character. Text is NUL-padded on write and ends at the first NUL on read. Text longer than the length is refused, not cut.

Symbolic Tag Map​

The tag map lets functions use a friendly name (Press.Count) instead of an address (DM100). Each tag maps a name to a device, a data type and, for strings, a length:

FieldRequiredDescription
nameYesTag name, unique within the connection
deviceYesDevice address, e.g. DM100 or MR1203
dataTypeYesBIT, WORD, INT, DWORD, DINT, REAL, LREAL or STRING
lengthNoString length in bytes, for STRING tags

Saving refuses a duplicate name, an address that does not parse, or a data type the device cannot hold (DM100 as BIT).

Importing tags (CSV or JSON)​

Paste tags into the Import box and click Import Tags.

name,device,dataType,length
Press.Count,DM100,DINT
Press.Alarm,MR1203,BIT
Press.Lot,DM300,STRING,10
[
{ "name": "Press.Count", "device": "DM100", "dataType": "DINT" },
{ "name": "Press.Alarm", "device": "MR1203", "dataType": "BIT" }
]

Function Builder​

Creating Keyence Functions​

After the connection is saved:

  1. Open the connection and go to the Functions tab
  2. Click New Function and choose Read Device, Read Block (Multi) or Write Device
  3. Fill the Basic fields (name, description, labels) and the Configuration fields
  4. Use Test Function to run it against the live PLC before saving

Read Device (keyence.read.device)​

Read one typed value from a device or tag, or Count consecutive values as a list.

FieldRequiredDefaultDescription
Device / TagYes—A device address (DM100, MR1203, T5, DM100.05) or a tag name
Data TypeNoWORDHow to interpret the value
CountNo1Consecutive values to read (1–1000). More than 1 returns a list. Ignored for STRING.
String LengthNo1Bytes, for STRING
TimeoutNo30mBound on this operation

A read larger than one request carries is split into several requests.

Read Block (Multi) (keyence.read.block)​

Read many named points. Each point has a name (the key in the result; names must be unique), a device (address or tag), a data type, and for strings a length. Neighbouring addresses of the same device type share one request, and no request exceeds the PLC's count limit. If any point is invalid, nothing is sent.

Write Device (keyence.write.device)​

Write one typed value, or a JSON list such as [1, 2, 3] to consecutive devices in one request.

FieldRequiredDefaultDescription
Device / TagYes—A writable device address or a tag name
Data TypeNoWORDHow to encode the value
ValueYes—The value, or a JSON list. Supports ((paramName)) templates.
String LengthNo1Bytes, for STRING
TimeoutNo30mBound on this operation
  • A single relay BIT is set or reset on its own (ST / RS); a list of bits is written in one request. A bit inside a word (DM100.05) is read, changed and written back as its word.
  • The whole value is checked before anything is sent. A value the type cannot hold, a non-whole number for an integer type, or text longer than the string length is refused.
  • A write that would need more than one request (over 1000 words on KV, 256 on a KV Nano) is refused, so a list is never half written.
  • A write is sent once. If the PLC does not answer in time, the result says so; MaestroHub does not repeat the write, because the PLC may already have applied it.

Using Parameters​

The Value field supports ((parameterName)) placeholders; they appear in the Function Parameters block, where you set each one's type, whether it is required, and a default. For example, Device DM200, Data Type REAL, Value ((setpoint)) writes the node's setpoint parameter to DM200.

Testing Functions​

Click Test Function on the function form, enter values for any ((parameters)), and click Execute Test. The dialog shows the decoded value or the PLC's error reply. You do not need to save the function first. Testing a Write Device function writes to the PLC.

Pipeline Integration​

Each operation has its own node: Keyence Read (connected.keyence.read.device), Keyence Block Read (connected.keyence.read.block) and Keyence Write (connected.keyence.write.device), plus the Keyence Read Group (connected.keyence.readgroup) for several reads in one node. To poll a PLC, drive the reads from a Schedule trigger.

See Keyence KV Nodes for the node reference.

Common Use Cases​

Line monitoring to a historian or the UNS​

A Read Block of the line's counts, speeds and alarm relays on a Schedule trigger, routed to the Unified Namespace or a historian.

Setpoints and recipes​

Parameterized Write Device functions (Value: ((setpoint))) fed from an MES or an operator form, with a Condition node checking the range first.

Machine control relays​

Set or reset MR relays to acknowledge alarms or start sequences. Only the addressed bit changes.

Troubleshooting​

Connection Issues​

SymptomPossible causeSolution
Test Connection times outNothing listening on that address and port, or a firewallCheck the PLC's IP address and Host Link port (8501 by default) in KV STUDIO, and that the port is reachable from MaestroHub.
the PLC refused the request (E1 …) on Test ConnectionThe port answers but is not a KV Host Link serverPoint the connection at the PLC's Host Link port.
Connections drop when several clients pollThe PLC serves a small number of Host Link connectionsUse one MaestroHub connection per PLC and group reads into Read Block or Read Group nodes.

Read / Write Issues​

SymptomPossible causeSolution
E0: device number out of rangeThe address does not exist on this model, or the read runs past its endCheck the device range for your model in the KV manual.
E2: no program, or the RUN/PROG switch is at PROGThe PLC is in PROGRAM modeSwitch the PLC to RUN. The failure is transient, so a retry succeeds once it is running.
E4: write-protectedThe device is write-protected in the PLCRemove the protection in KV STUDIO, or write another device.
DM0 (Data memory) is a word device: use WORD …BIT chosen on a data-memory deviceRead relays as BIT; read data memory as a word type.
A W or B address reads the wrong valueHex numbering: W20 is register 32Write the address in hexadecimal.
MR1216 … bit 16 is not 00-15The last two digits of a relay are the bitMR1216 does not exist; the bit after MR1215 is MR1300.
A STRING reads only two charactersString Length left at 1Set the length in bytes on both the write and the read.
Japanese or Cyrillic text reads as garbageWrong String EncodingSet the connection's String Encoding to shift-jis or windows-1251.