SAML2 Webapp Addon unintended behaviour

I’m afraid some additional context will be required in order to further troubleshoot this situation. In particular, you mention two applications; do each have their own client application record in Auth0? Can you reproduce the issue on the SAML one without the embedding on the other one (no iframes, just accessing the SAML one even if from an UI perspective this does not make sense)? The more we reduce the repro steps the easier it will be to troubleshoot. Also, you should provide the configuration you’re using (you can redact the sensitive parts like app specific URL’s).