Speedometer-style dials for bounded sensor fields (speed, RPM, engine temp, throttle, fuel, battery). Color zones are
reasonable defaults for a typical commuter motorcycle, not a certified warning
system for your specific bike — see js/core/GaugeRenderer.js to tune them.
Trend lines for numeric fields, built from frames received this session (not persisted across reloads). Select multiple fields to overlay.
Vehicle & Dongle Info
On-demand register reads via the VarEx command channel. Experimental — see code comments in js/core/BleConnection.js.
—
Security / Handshake fields experimental
click to expand
Shape and purpose of these fields weren't confirmed from decompilation (see docs/BLE_PROTOCOL.md §4). Reading them is passive/non-destructive — results are just raw bytes to inspect.
—
Write-targeted registers handle with care
click to expand
In the OEM app these addresses are where commands get written (registration, FOTA trigger, phone control). This tool only ever sends a read opcode to them — never a write — but we can't guarantee every dongle firmware treats an unexpected read as side-effect-free. Read one at a time and watch the Raw Frames tab if you try these. Excluded from Full Scan by default.
—
Trip log and stat log pointers/counters, plus a raw paged dump of the large log regions. Record layout
inside TRACKLOG_PTR/statlog_PTR isn't documented — this surfaces raw bytes for
your own analysis (export and diff across rides to spot patterns).
—
Read-only. Shows firmware/FOTA status fields. There is no button here to trigger a FOTA
update (cmmdFota) — see docs/research/BLE_SECURITY_FINDINGS.md for why this tool
never writes to the command channel.
—
Walks every known register tag from assets/bleSpec.csv with a read-only VarEx request and reports
whatever comes back — the fastest way to pull the maximum amount of information off the dongle in one pass.
Still zero writes: this never touches REGPROC_W/cmmdFota/phoneControl unless you explicitly opt in below, and even then only reads them.
| Tag | Group | Address | Len | Status | Hex | ASCII | Description |
|---|
If "Connect to Bike" or "Scan All (debug)" connects but then fails with "doesn't expose the expected vehicle service", your dongle is a different hardware revision than the one this app's protocol was reverse-engineered from. This tool requests access to all 256 possible service codes in the same UUID family and reports back whichever ones your specific device actually has — read-only GATT discovery, no data is written.
Edit the field byte/bit offsets live and re-decode without touching code. Changes persist to
localStorage for this browser only. Use "Reset to defaults" to discard edits.
Settings persist to localStorage for this browser only.