Projects and partners

A working checkout still needs an HTTPS renewal owner

Identify the certificate service from the store's genuine service and configuration records, then obtain a named team's acknowledgment of renewal responsibility for the exact hostname. Keep current certificate validity, a past renewal and responsibility for the next renewal separate. A checkout that works today does not identify its renewal owner or establish automatic renewal. Record the dependency and escalation route without changing certificate or domain configuration.

For: A research-only merchant or authorized project lead checking ongoing HTTPS responsibility during a website or vendor handoff.

Updated 2026-10-01

Current HTTPS is a condition, not a handoff record

The WooCommerce Stripe express-checkout documentation requires a valid SSL certificate for the domain and HTTPS across the entire site. It also describes additional method-specific domain and security requirements. Those requirements explain why the merchant should keep HTTPS responsibility visible after delivery. They do not say which company renews a particular store's certificate.

A currently usable checkout answers an observation about the site now. It does not answer who receives a renewal notice, which service manages the certificate or who is responsible if renewal needs attention. The task here is to establish those operating dependencies, not to diagnose a missing wallet button or change security settings.

Connect the exact hostname to the real service

List the store hostname buyers use and any separate checkout hostname that is actually part of the site's current journey. For each, locate the corresponding certificate-management record through an authorized service account or a configuration record supplied by the responsible team. Keep the public hostname in the worksheet; do not copy private checkout-session links.

Record both the certificate information you can observe and the service the team identifies as managing it. Do not assign renewal to a hosting company merely because it hosts the website, or to the agency merely because it built checkout. Require a record connecting the hostname to that service and an acknowledgment of the responsibility being handed over.

If the hostname is documented but the managing service is unknown, name that exact gap. If the service is identified but the merchant cannot reach an authorized contact, record the contact dependency separately. Combining these into a single 'SSL complete' checkbox would hide what remains to be established.

Separate the certificate date from the renewal commitment

Copy a known certificate expiry date or a real renewal event only with its source and observation date. If a service record shows a scheduled renewal, describe it as the service's stated schedule. If a completed event is recorded, describe that event. A date copied without identifying the certificate or hostname cannot establish coverage for this checkout.

Ask the responsible team to identify the renewal arrangement for the actual service. Where automation is claimed, record the service evidence and who is responsible for responding when it reports a problem. Do not mark renewal as automatic based solely on a working HTTPS page or a past successful renewal. This worksheet supplies no universal renewal interval or provider-specific instructions.

During a vendor change, compare the recorded arrangement with the agreed scope after handoff. Determine whether the same team continues to own it, whether another team has accepted it or whether responsibility remains undecided. A proposed new owner belongs in the open questions until that team acknowledges the hostname and work.

Close the responsibility gap without editing the setup

A usable HTTPS dependency record identifies the hostname, managing service, responsible team, available renewal evidence and a route for raising a problem. Add the merchant contact who can coordinate action and any genuine deadline already documented. If a role or record is missing, give the follow-up a named owner rather than treating the current checkout as proof that the dependency is covered.

Do not change certificates, DNS, HTTPS settings or validation files merely to complete this inventory. It is enough to document the current arrangement and identify who can evaluate an actual change. An existing warning or expired-certificate record belongs with the responsible service team as a concrete finding; this page does not promise a restoration time.

For a scoped Prism checkout consultation, provide the public website, research-only products and a concise explanation of the unresolved dependency. Prism's published support is storefront review, processing preparation and help with provider website questions. Confirm any requested certificate-related assistance, responsibilities, fees and terms before work. The merchant decides which changes to make, and the provider separately decides processing eligibility. The inquiry receives email follow-up and is not a booking, purchase or processing application.

HTTPS dependency record

Complete this for each actual store or checkout hostname. Keep observed validity, documented renewal behavior and assigned responsibility separate. An unknown service or unacknowledged owner remains an open handoff item even when the page currently loads.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

HTTPS dependency record. The last column is for temporary notes.
DependencyEvidence to useWhat remains unproven without itYour record
Store hostnameExact public hostname used in the buyer journey and the dated observation or configuration record identifying it.A certificate record for another hostname does not establish this dependency.
Certificate serviceAuthorized service record or documented configuration linking this hostname to its certificate-management service.The website host or project vendor cannot be assumed to manage renewal.
Actual renewal ownerNamed team and its acknowledgment of responsibility for this hostname under the current service arrangement.A contact name without accepted responsibility does not close the handoff.
Known expiry or renewal recordCertificate validity information, recorded renewal event or stated schedule, with its source and observation date.Current validity, past completion and a future schedule are different evidence.
Claimed renewal automationThe actual service record supporting the claim and the team responsible for responding to a problem.A working checkout alone cannot establish automatic renewal or future success.
Escalation routeDocumented service contact or support route and the authorized merchant contact who coordinates it.A route that nobody has identified leaves the dependency unresolved; do not invent a response-time commitment.
Handoff dependencyAny change of responsible team, the receiving team's acknowledgment and the real date or unresolved condition.Delivery of the website does not establish continuity of certificate responsibility.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • WooCommerce Stripe express-checkout HTTPS requirements apply to that integration. Technical functionality does not establish processing eligibility or legal approval.
  • This record does not configure or renew a certificate, guarantee automatic renewal, establish a monitoring service or promise incident response.
  • Keep certificate private keys, passwords, authentication codes, API secrets and customer or payment records out of the worksheet and public inquiry.

Sources

  • WooCommerce Stripe express checkouts — checked 2026-09-29. The documented Stripe extension express-checkout setup requires a valid domain SSL certificate and sitewide HTTPS, with additional method-specific domain and security conditions. It does not identify a merchant's renewal service or owner.
  • Prism: How it works — checked 2026-09-21. Consultation scope defines pages, questions and follow-up before work; the merchant chooses changes. No response time is stated.
  • Prism solutions — checked 2026-09-21. Published support covers storefront review, processing preparation and provider website questions, with scope, fees and terms discussed before work. The provider decides account eligibility and terms.
  • Prism contact — checked 2026-09-21. The inquiry asks for the website, products and question while excluding passwords, payment-card details and customer records. Email follow-up does not book an appointment, buy a service or submit a processing application.

Discuss my store project

Planning, moving or taking over a store?