I may have misinterpreted your question entirely. If you're speaking only about metadata, then yes, every SAML assertion must be sent to an endpoint that is listed as valid in the SP's metadata. So yes, you would put endpoints for both domains in there, just as you would different ports or paths. Again, I'm sorry for spamming you.