Cannot access cloud-run webapp with IAP

Hi guys,
after reading all documentation and spending hours with LLM support to fix my problem, you are my last resort. I deployed a streamlit app with cloud-run and IAP active. But i always get the access denied site when I try the URL. I have set all roles accordingly and even check the roles of the IAP agent. But it is impossible to access my app. When i turn it to a public page, it works fine.
Probably, I have spent more than 8 hours on this problem. Deleted the whole service and deployed again but Im stuck with the same problem :confused: any ideas, that a standard LLM would not propose? Thanks four your help!!