T4L Agent
t4l-agent runs one T4L connector and one coach loop against an existing OpenClaw agent.
OpenClaw owns the model, provider, reasoning mode, credentials, tools, and native session execution. T4L keeps those choices unchanged.
The whole runtime
T4L Trainer phone
|
| signed HTTPS
v
OpenClaw t4l-connect plugin
|
| narrow loopback proxy
v
t4l-agent run
├─ t4l-server + SQLite
└─ coach loop -> existing OpenClaw agent
There are two production commands:
t4l-agent installprepares an existing supported OpenClaw VPS.t4l-agent runruns the connector after setup.
Easy VPS setup
The normal user does not need to assemble Python or npm commands. Their trusted host agent reads the T4L install runbook and runs the pinned bootstrap:
curl -fsSL --proto '=https' --tlsv1.2 \
https://raw.githubusercontent.com/BigSlikTobi/t4l-agent/v0.4.0/install.sh \
| sudo bash -s -- \
--public-url https://coach.example.com \
--connector-owner-id webchat:gateway:operator-admin
The host agent supplies the real public URL and the exact verified
channel:account:sender identity. It also passes --openclaw-executable when
OpenClaw is installed outside the administrator's normal PATH. The script:
- creates one private Python environment under
/opt/t4l; - installs exactly
t4l-agent 0.4.0andt4l-server 0.9.0from PyPI; - checks the existing OpenClaw agent without sending a channel message;
- installs and pins the
t4l-connect 0.4.0plugin through OpenClaw; - creates the shared host-only token and loopback systemd service;
- checks the local connector and the restricted public HTTPS route.
This release supports Linux, Python 3.11+, and either a system-level or
current-user systemd OpenClaw Gateway owned by the administrator running the
installer. It stops safely when it cannot identify one exact Gateway service.
It never opens ports 18789 or 8787.
If the local service is ready but the existing reverse proxy still needs its
narrow T4L route, the installer reports LOCAL_READY. That is not full success.
The host agent finishes the proxy work and reruns the acceptance check.
What setup creates
The host setup does this once:
- Install the
@t4l-trainer/openclaw-t4l-connectplugin in the existing OpenClaw profile. - Configure its
agentIdand loopbackconnectorBaseUrl, normallyhttp://127.0.0.1:8787. - Give both the OpenClaw Gateway and
t4l-agentthe same randomT4L_CONNECTOR_RUNTIME_TOKEN. - Start
t4l-agent run.
The plugin contains only:
- the authenticated pre-model
/t4l connect CODEcommand; - a strict allowlist of phone routes;
- an HTTPS-to-loopback proxy.
The plugin itself does not install packages, choose releases, manage services, or receive provider credentials. The separate host installer owns that work.
For local plugin development:
cd openclaw_plugins/t4l-connect
npm test
npm pack --dry-run
Install a published version with OpenClaw's normal pinned-plugin flow. Configure it through the OpenClaw control surface for the selected profile.
Install the Python runtime
Python 3.11 or newer is required. Install t4l-server and t4l-agent into the same environment.
For local development:
python3 -m venv .venv
.venv/bin/pip install -e ../t4l-server
.venv/bin/pip install -e '.[dev]'
Run
export T4L_CONNECTOR_RUNTIME_TOKEN='replace-with-a-long-random-secret'
t4l-agent run \
--agent-id main \
--agent-name Atlas \
--agent-profile coach-01 \
--connector-owner-id 'slack:workspace-id:user-id' \
--data-dir /srv/t4l/coach-01 \
--host 127.0.0.1 \
--port 8787
The owner identity is exactly channel:account:sender. Repeat --connector-owner-id for multiple authenticated owner channels.
Use the existing OpenClaw profile and agent id. Optional --agent-home-dir, --agent-state-dir, and --agent-config-path flags point at that runtime. T4L never creates a second agent.
The connector binds to loopback by default. The phone enters the public HTTPS OpenClaw Gateway address, not the loopback connector address. Public binding requires --allow-public-bind and still requires trusted HTTPS.
T4L_SERVER_API_KEY may provide a stable host-only MCP key. Otherwise the process creates one. The phone never receives it.
Phone connection
- The phone enters the Gateway address.
- It creates an Ed25519 key and receives an eight-character pairing code.
- It shows
/t4l connect XXXX-XXXX. - The user sends that command in an authenticated OpenClaw owner channel.
- The plugin forwards only the code and verified owner identity to the loopback connector.
- The phone proves key possession and receives a device-bound token scoped to
chat,sync, andstatus.
There is no post-pair installer, release selection, rollback job, second code, API-key form, or model-driven host setup.
Coach behavior
The coach loop uses the existing OpenClaw agent with no provider, model, reasoning, or delivery override. Every turn uses a fresh isolated session key. It does not send a message through OpenClaw channels; the reviewed reply returns through T4L chat.
Purpose-specific instructions are embedded in the Python package:
core.mdonboarding.mdchat.mdtraining-block.md
The loop loads only the files needed for the current turn.
Onboarding starts in the phone language (German, English, or Spanish) and
follows an explicit athlete language change. One fixed T4L Gym Bro helps the
athlete choose a playful training theme, gathers the practical limits one at a
time, then proposes one four-week mission and two or three measurable checks.
Checks use semicolons: first check; second check, with an optional third.
Replies may include up to four localized smart answers. A smart confirmation is bound to
the exact setup summary it accepts; older text-only clients remain supported.
Runtime, provider, model, and reasoning diagnostics are never added to the
athlete-facing introduction.
Smart replies require t4l-server 0.9.0 or newer so the server response echoes
the stored choices. The agent reports an incompatible server instead of
silently dropping chips.
The phone remains authoritative:
- onboarding produces a pending
athlete_setup_draft.v1; - planning produces a pending
training_block_plan.v1; - the phone explicitly reviews and accepts both;
- the phone chooses the daily workout variant locally;
- agent chat cannot silently rewrite accepted state.
Exercise videos must be exact YouTube Shorts for the selected exercise. The host verifies the URL and live title before storing a plan.
The coach is training-and-recovery only. Nutrition, hydration, supplement, weight, and body-composition prescriptions are blocked before and after model execution.
Development
.venv/bin/ruff format --check .
.venv/bin/ruff check .
.venv/bin/mypy
.venv/bin/pytest -q
cd openclaw_plugins/t4l-connect
npm test
npm pack --dry-run
The tests use runtime fakes. Before production, also run one live OpenClaw smoke test for:
- runtime readiness;
- non-delivering coach execution;
- owner and non-owner pairing commands;
- the Gateway HTTPS proxy;
- a complete phone pairing and training-block review round trip.
Metadata
Release files for t4l-agent 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| t4l_agent-0.4.0.tar.gz | 72.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| t4l_agent-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 125.1 kB
Release files / t4l_agent-0.4.0.tar.gz
| Download URL | t4l_agent-0.4.0.tar.gz |
|---|---|
| Size | 72.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ecf81bce86b8e3fa1620151307fd08ef93376bd927ad1fd1b0e79ae606073e58
|
|
BLAKE2b-256 checksum How to use checksums |
7ae60a4a73b2f6951c3ae533203db8ee9bbd9419f026c70da3e8a7d524cf126b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.
Transparency logRelease files / t4l_agent-0.4.0-py3-none-any.whl
| Download URL | t4l_agent-0.4.0-py3-none-any.whl |
|---|---|
| Size | 52.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
33747b99f7914994724eaaa5b682902375c8c6dd97c501792fcc65e9b1c320fd
|
|
BLAKE2b-256 checksum How to use checksums |
f69e704238175b6fba1d48da52ecad1c9e60d74825c4b296ca425c3591875152
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.
Transparency log