Skip to main content

T4L Agent

t4l-agent runs one T4L connector and one coach loop against an existing OpenClaw agent.

OpenClaw owns the model, provider, reasoning mode, credentials, tools, and native session execution. T4L keeps those choices unchanged.

The whole runtime

T4L Trainer phone
        |
        | signed HTTPS
        v
OpenClaw t4l-connect plugin
        |
        | narrow loopback proxy
        v
t4l-agent run
  ├─ t4l-server + SQLite
  └─ coach loop -> existing OpenClaw agent

There are two production commands:

  • t4l-agent install prepares an existing supported OpenClaw VPS.
  • t4l-agent run runs the connector after setup.

Easy VPS setup

The normal user does not need to assemble Python or npm commands. Their trusted host agent reads the T4L install runbook and runs the pinned bootstrap:

curl -fsSL --proto '=https' --tlsv1.2 \
  https://raw.githubusercontent.com/BigSlikTobi/t4l-agent/v0.4.0/install.sh \
  | sudo bash -s -- \
      --public-url https://coach.example.com \
      --connector-owner-id webchat:gateway:operator-admin

The host agent supplies the real public URL and the exact verified channel:account:sender identity. It also passes --openclaw-executable when OpenClaw is installed outside the administrator's normal PATH. The script:

  1. creates one private Python environment under /opt/t4l;
  2. installs exactly t4l-agent 0.4.0 and t4l-server 0.9.0 from PyPI;
  3. checks the existing OpenClaw agent without sending a channel message;
  4. installs and pins the t4l-connect 0.4.0 plugin through OpenClaw;
  5. creates the shared host-only token and loopback systemd service;
  6. checks the local connector and the restricted public HTTPS route.

This release supports Linux, Python 3.11+, and either a system-level or current-user systemd OpenClaw Gateway owned by the administrator running the installer. It stops safely when it cannot identify one exact Gateway service. It never opens ports 18789 or 8787.

If the local service is ready but the existing reverse proxy still needs its narrow T4L route, the installer reports LOCAL_READY. That is not full success. The host agent finishes the proxy work and reruns the acceptance check.

What setup creates

The host setup does this once:

  1. Install the @t4l-trainer/openclaw-t4l-connect plugin in the existing OpenClaw profile.
  2. Configure its agentId and loopback connectorBaseUrl, normally http://127.0.0.1:8787.
  3. Give both the OpenClaw Gateway and t4l-agent the same random T4L_CONNECTOR_RUNTIME_TOKEN.
  4. Start t4l-agent run.

The plugin contains only:

  • the authenticated pre-model /t4l connect CODE command;
  • a strict allowlist of phone routes;
  • an HTTPS-to-loopback proxy.

The plugin itself does not install packages, choose releases, manage services, or receive provider credentials. The separate host installer owns that work.

For local plugin development:

cd openclaw_plugins/t4l-connect
npm test
npm pack --dry-run

Install a published version with OpenClaw's normal pinned-plugin flow. Configure it through the OpenClaw control surface for the selected profile.

Install the Python runtime

Python 3.11 or newer is required. Install t4l-server and t4l-agent into the same environment.

For local development:

python3 -m venv .venv
.venv/bin/pip install -e ../t4l-server
.venv/bin/pip install -e '.[dev]'

Run

export T4L_CONNECTOR_RUNTIME_TOKEN='replace-with-a-long-random-secret'

t4l-agent run \
  --agent-id main \
  --agent-name Atlas \
  --agent-profile coach-01 \
  --connector-owner-id 'slack:workspace-id:user-id' \
  --data-dir /srv/t4l/coach-01 \
  --host 127.0.0.1 \
  --port 8787

The owner identity is exactly channel:account:sender. Repeat --connector-owner-id for multiple authenticated owner channels.

Use the existing OpenClaw profile and agent id. Optional --agent-home-dir, --agent-state-dir, and --agent-config-path flags point at that runtime. T4L never creates a second agent.

The connector binds to loopback by default. The phone enters the public HTTPS OpenClaw Gateway address, not the loopback connector address. Public binding requires --allow-public-bind and still requires trusted HTTPS.

T4L_SERVER_API_KEY may provide a stable host-only MCP key. Otherwise the process creates one. The phone never receives it.

Phone connection

  1. The phone enters the Gateway address.
  2. It creates an Ed25519 key and receives an eight-character pairing code.
  3. It shows /t4l connect XXXX-XXXX.
  4. The user sends that command in an authenticated OpenClaw owner channel.
  5. The plugin forwards only the code and verified owner identity to the loopback connector.
  6. The phone proves key possession and receives a device-bound token scoped to chat, sync, and status.

There is no post-pair installer, release selection, rollback job, second code, API-key form, or model-driven host setup.

Coach behavior

The coach loop uses the existing OpenClaw agent with no provider, model, reasoning, or delivery override. Every turn uses a fresh isolated session key. It does not send a message through OpenClaw channels; the reviewed reply returns through T4L chat.

Purpose-specific instructions are embedded in the Python package:

  • core.md
  • onboarding.md
  • chat.md
  • training-block.md

The loop loads only the files needed for the current turn.

Onboarding starts in the phone language (German, English, or Spanish) and follows an explicit athlete language change. One fixed T4L Gym Bro helps the athlete choose a playful training theme, gathers the practical limits one at a time, then proposes one four-week mission and two or three measurable checks. Checks use semicolons: first check; second check, with an optional third. Replies may include up to four localized smart answers. A smart confirmation is bound to the exact setup summary it accepts; older text-only clients remain supported. Runtime, provider, model, and reasoning diagnostics are never added to the athlete-facing introduction.

Smart replies require t4l-server 0.9.0 or newer so the server response echoes the stored choices. The agent reports an incompatible server instead of silently dropping chips.

The phone remains authoritative:

  • onboarding produces a pending athlete_setup_draft.v1;
  • planning produces a pending training_block_plan.v1;
  • the phone explicitly reviews and accepts both;
  • the phone chooses the daily workout variant locally;
  • agent chat cannot silently rewrite accepted state.

Exercise videos must be exact YouTube Shorts for the selected exercise. The host verifies the URL and live title before storing a plan.

The coach is training-and-recovery only. Nutrition, hydration, supplement, weight, and body-composition prescriptions are blocked before and after model execution.

Development

.venv/bin/ruff format --check .
.venv/bin/ruff check .
.venv/bin/mypy
.venv/bin/pytest -q

cd openclaw_plugins/t4l-connect
npm test
npm pack --dry-run

The tests use runtime fakes. Before production, also run one live OpenClaw smoke test for:

  • runtime readiness;
  • non-delivering coach execution;
  • owner and non-owner pairing commands;
  • the Gateway HTTPS proxy;
  • a complete phone pairing and training-block review round trip.

Metadata

Release files for t4l-agent 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for t4l-agent 0.4.0
File Size Uploaded
t4l_agent-0.4.0.tar.gz 72.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for t4l-agent 0.4.0
File Interpreter ABI Platform
t4l_agent-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 125.1 kB

Release files / t4l_agent-0.4.0.tar.gz

Download URL t4l_agent-0.4.0.tar.gz
Size 72.7 kB
Tags Source
SHA-256 checksum
How to use checksums
ecf81bce86b8e3fa1620151307fd08ef93376bd927ad1fd1b0e79ae606073e58
BLAKE2b-256 checksum
How to use checksums
7ae60a4a73b2f6951c3ae533203db8ee9bbd9419f026c70da3e8a7d524cf126b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.

Transparency log

Release files / t4l_agent-0.4.0-py3-none-any.whl

Download URL t4l_agent-0.4.0-py3-none-any.whl
Size 52.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
33747b99f7914994724eaaa5b682902375c8c6dd97c501792fcc65e9b1c320fd
BLAKE2b-256 checksum
How to use checksums
f69e704238175b6fba1d48da52ecad1c9e60d74825c4b296ca425c3591875152
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

0.3.2

2 release files

0.3.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page