Program a PLC in your browser
Build ladder logic, press RUN and watch a conveyor, tank, traffic light, batch mixer or a virtual ESP32 board respond. The notes under the PLC explain each rung while it runs. Plug in an ESP32 by USB and real buttons and lights follow your program too.
Scan status
Rung by rung
Outputs, memory & timers
Connect a real ESP32
Plug an ESP32 into your computer by USB (an ESP32-C3 SuperMini, a classic ESP32 DevKit or an ESP32-S3) and your ladder program drives real LEDs and relay modules, with real push-buttons as inputs. Upload the free PickettPLC firmware once, then press ⚡ CONNECT in the ESP32 bar. The simulation switches to the ESP32 Board view, and the on-screen PRESS buttons keep working alongside the real ones, so an input you add on screen can switch the board's outputs. No board yet? Pick ESP32 Board in the simulation list to try it virtually. USB needs Chrome or Edge on a computer.
Ladder logic, step by step
Ten short lessons, from how a PLC scans to why the emergency stop never lives only in the program. Most have a button that loads a working example into the PLC above.
SCANThe scan cycleHow a PLC thinks, over and over
A PLC doesn't react to inputs the instant they change. It runs a loop called the scan:
- Read inputs: take a snapshot of every input.
- Solve the logic: work through the rungs top to bottom, left to right, using that snapshot.
- Write outputs: update the real outputs all at once.
This simulator scans every 100 ms so you can watch it happen. Real PLCs typically scan in 1 to 20 ms. Rung order matters: a rung can use a bit that an earlier rung wrote in the same scan.
-| |-NO and NC contactsAsking "is this bit on or off?"
A contact in ladder logic isn't a physical switch. It's a question about a bit:
- NO (normally open), -| |-: passes power when the bit is 1. Also called "examine if closed" (XIC).
- NC (normally closed), -|/|-: passes power when the bit is 0. Also called "examine if open" (XIO).
In this simulator the STOP button is a push-button that reads 1 while pressed, so the program uses an NC contact to break the rung.
SEALThe seal-in (latching) circuitKeep a motor running after START is released
A START push-button is only pressed for a moment. To keep the motor running, the output "holds itself in" with a contact in parallel with START:
Press START and the rung energises. The MOTOR contact closes, so when START is released power still flows through it. Pressing STOP breaks the rung and the seal drops out.
This is the same circuit electricians wire with a contactor's auxiliary contact. The PLC version here uses memory bit M0.0 as the seal.
(S)(R)SET and RESET coilsLatches that remember
A normal coil ( ) follows its rung every scan. A SET coil (S) turns its bit on and leaves it on. A RESET coil (R) turns it off. Some other rung has to undo what SET did.
SET/RESET is ideal for step sequences, where one event starts a step and a different event ends it. Keep the SET and RESET for the same bit easy to find, or the program becomes hard to follow.
This simulator clears all outputs and memory when you press STOP. Real PLCs can keep chosen bits through a power cut: that's called retentive memory.
-|P|-Edge detection (one-shots)Act once per press, not every scan
A positive edge contact -|P|- passes power for exactly one scan, when its bit changes from 0 to 1. A negative edge -|N|- does the same when it changes from 1 to 0.
Use one-shots when something should happen once per event: counting boxes, stepping a sequence, or toggling a light with one button. Without them, holding a button for half a second would count five times at a 100 ms scan.
TONOn-delay and off-delay timersTON, TOF and the done bit
- TON (on-delay): while its rung is true, the accumulator counts up. When it reaches the preset, the done bit (DN) turns on. If the rung goes false, it resets to zero.
- TOF (off-delay): DN turns on straight away with the rung, and stays on for the preset time after the rung goes false.
Use a TMR DONE contact -|T|- to use a timer's DN bit in another rung.
I Q MAddresses: I, Q, M and TWhere every bit lives
- I = inputs (buttons, sensors).
I0.2means input byte 0, bit 2. - Q = outputs (contactors, lamps, valves).
- M = memory bits, also called markers or internal relays. They exist only inside the PLC.
- T = timers, each with a preset, an accumulator and a done bit.
This byte.bit style is used by Siemens and many others. Allen-Bradley uses tag names or addresses like I:0/2, but the idea is the same.
STEPStep sequencesFill, mix, drain: one step at a time
Machines usually work in steps. A clean way to program that is one memory bit per step, with exactly one step active at a time:
- An event (START, a sensor, a timer's DN) RESETs the current step and SETs the next.
- Each step bit drives its outputs with normal coils.
This makes faults easy to find: whichever step bit is on tells you exactly where the machine is waiting.
2×( )Never use a coil twiceThe "double coil" trap
If two rungs both drive ( Q0.0 ), most PLCs simply let the last rung win, because it writes last in the scan. The first rung might as well not be there, and the fault is very hard to spot on a live machine.
If several conditions should run the same output, put them in parallel branches on one rung instead, or combine them through memory bits.
E-STOPSafety: the PLC is not the E-stopWhy safety is hardwired
A standard PLC can crash, stall or be programmed wrongly. So an emergency stop must remove the hazard through a hardwired safety circuit: a safety relay or a certified safety PLC dropping out the contactors directly.
The standard PLC is usually given a contact from the safety circuit so it knows the E-stop was pressed and can show a message, but it is never the thing that stops the machine.
To see how hardwired control circuits are built from contacts and relays, try PickettPanel Lite.
Open PickettPanel Lite ↗Build it yourself
Three small jobs of the kind you'd get on a real machine. Try each one in the editor first. If you get stuck, load a working solution and compare.
Stop the conveyor at the sensor
The conveyor should start and stop with its buttons as normal, but also stop by itself when the box reaches sensor I0.2.
Add an NC contact for I0.2 to both branches of the seal-in rung, just like STOP.
3-second start warning
After START, wait 3 seconds before the motor runs, so people have time to stand clear. STOP must still work at any time.
Seal in a RUN bit (M0.0). Drive a TON timer from M0.0 with a 3000 ms preset. Use the timer's DN contact to run Q0.0.
Add a JOG button
Maintenance want a JOG button (I0.4) that runs the motor only while it's held, alongside the normal START/STOP. Watch out for the double-coil trap.
Seal in M0.0 with START/STOP. Then drive Q0.0 from one rung with two parallel branches: M0.0 or I0.4.
Check yourself
Six questions. Pick an answer to see the explanation.
Instruction reference
Every instruction in the toolbar, what it looks like, and what it does.
-| |-NO contactPasses power when the bit is 1.-|/|-NC contactPasses power when the bit is 0.-|P|-Positive edgePasses for one scan when the bit goes 0 → 1.-|N|-Negative edgePasses for one scan when the bit goes 1 → 0.-( )-Output coilBit = 1 while the rung is true, 0 when it isn't.-(/)-Negated coilBit = 0 while the rung is true, 1 when it isn't.-(S)-Set coilTurns the bit on and leaves it on.-(R)-Reset coilTurns the bit off and leaves it off.[TON]On-delay timerDN turns on after the rung has been true for the preset time.[TOF]Off-delay timerDN stays on for the preset time after the rung goes false.-|T|-Timer done contactPasses power when that timer's DN bit is on.I · Q · M · TAddress typesInputs, outputs, memory bits and timers.From ladder logic to real wiring
Ladder diagrams started life as relay circuits. PickettPanel Lite lets you build the hardwired version with contacts, coils and pilot lamps, the way it's done in a control panel.