Changing your primary domain: what follows you, and what you have to point
Every claim below was tested live on this store by actually changing its Store URL and re-clicking the same links.
The one thing worth understanding
Your store’s data does not live in WordPress. Products, customers, orders, subscriptions and saved cards all live on the SureCart platform. WordPress is the storefront that renders them. What ties the two together is your API token, not your domain.
That is why the domain change is safe. It is also why there are exactly two values that do point at your domain, and both are updated from your WordPress admin.
Test it yourself
A real “manage your subscription” link, exactly as a customer received it
This is the live link for an active subscription on this store. Note that it is a surecart.com address, not this site’s address.
Click it. It resolves your Store URL at the moment of the click and forwards to whatever domain your store currently points to. Change the domain, and this same link, already sitting in inboxes, follows it. Nothing to regenerate.
A checkout link carrying a checkout_id
The checkout_id is a platform ID, not a WordPress one. Any domain running your store can open it.
What was actually tested
This store’s Store URL was temporarily repointed to a different domain. The same links were then requested again, unchanged:
What is domain-bound and what is not
| Thing | Domain change | Why |
|---|---|---|
| Active subscriptions | No effect | Billed by the platform on a schedule. Your site is not consulted. |
| Saved cards | No effect | Held in the processor vault against the customer record. |
| Store connection | No effect | Authenticated by the API token in your database, which travels with it. |
| Stripe / PayPal webhooks | No effect | They post to api.surecart.com, never to your site. |
| Portal links in past emails | Follows you | They point at app.surecart.com and resolve at click time. |
| Checkout links | Follows you | checkout_id is a platform ID. A 301 that keeps the query string is enough. |
| Webhook URL | Update it | Stored as your old address. One click in the admin notice. |
| Store URL | Update it | Every portal link resolves through it. |
| Abandoned-cart emails | Keep the 301 | Each cart stores the address it was created on. See below. |
Abandoned-cart recovery emails are the single exception. Each checkout records the address it was created on, so recovery emails for carts created before the move keep pointing at the old domain permanently. Tested and confirmed: with the Store URL moved, subscription links followed, but an older checkout link still resolved to the original domain. Carts created after the move are fine. Your planned 301 covers exactly this, so keep it.
The order to do it in
- Get SSL on the new domain first
SureCart will not register or update a webhook over plain HTTP. A new subdomain needs its own certificate, so issue it before you load wp-admin on the new address.
- Change the domain and run the search-replace
Your API token is stored as an encrypted string that does not contain your domain, so a search-replace cannot corrupt it. Same install and same server means wp-config.php is untouched, which is what the token is encrypted against.
- Log into wp-admin on the new domain
A notice appears: “There are two websites connected to the same SureCart store.” Choose I Changed My Site Address. Do not choose the staging option, which would create a second connection.
- Update the Store URL
In app.surecart.com, set the store URL to the new domain. This is what every portal link in every past email resolves through.
- Verify
Tools → Site Health → Info → SureCart. API Connectivity should read Connected, and the registered webhook URL should show the new domain.
- Place one real test order
A 100% off coupon is enough. It proves the webhook round-trip end to end, which is the only part that actually changed.
Verified against the SureCart plugin and platform on 10 September 2026. The Store URL was returned to its original value after testing.