Home › Prompt Engineering › Delimiters & formatting
✍️ · Ground

Delimiters & formatting

Wrapping inputs and sections in explicit markers so the model can tell instructions from data.

In one line

Fencing each part of a prompt with clear delimiters makes the model less likely to confuse your data with your instructions.

ConceptWhat it is

Delimiters and formatting is the practice of surrounding each distinct part of a prompt — the instruction, retrieved documents, few-shot examples, and the user's raw input — with explicit markers so the model can see where one section ends and the next begins. Common conventions are XML-style tags like <doc>…</doc>, fenced headers like ### Task ###, and triple backticks around pasted content.

It exists because a prompt is just one flat stream of text to the model, which has no built-in way to know that a pasted paragraph is data to be processed rather than instructions to be followed. Clear fences make that boundary visible, cutting a common class of confusion and giving a modest amount of resistance to prompt injection.

How it worksThe mechanics

You pick one consistent marker style, wrap every section of the prompt in it, and label what each fence contains, so the assembled prompt becomes a sequence of clearly bounded blocks. The model reads these markers as structural cues, attends to the right span when you say something like "summarize only the text inside <article>", and is less likely to treat embedded text as a fresh instruction — though this is a strong learned tendency, not a hard guarantee.

At a glanceSee it

Delimiters & formatting diagram
Delimiters & formatting diagram 1

The delimiter-collision mechanism — when untrusted text smuggles a copy of your end marker, the model closes the section early and reads the rest as commands, which is why an unguessable per-request delimiter is the real defense.

Delimiters & formatting diagram 2

A decision path for picking one delimiter convention, driven by whether the content needs nested labeled fields and whether it already contains backticks that a naive fence would collide with.

When to use itWhere it fits

  • Multi-part prompts that pack instructions, context, and examples into one call.
  • RAG, where retrieved passages must stay visibly separate from the actual question.
  • Any prompt that mixes trusted instructions with untrusted user or third-party text.
  • When you want the model to map named input sections onto a structured output.

When NOT to use itLimits & anti-patterns

  • As your only defense against prompt injection — treat it as hygiene, not a security boundary.
  • Trivial single-instruction prompts where there is nothing to separate.
  • When over-nesting delimiters makes the prompt harder for humans to read than it helps the model.
  • Expecting markers to enforce output format on their own — pair them with a schema or examples.

Trade-offsAdvantages & costs

Advantages
  • Almost free: a few tokens of markup, no infrastructure and no added latency.
  • Cuts a common failure where the model treats data as instructions or the reverse.
  • Makes long, multi-part prompts easier for both the model and your team to read and edit.
  • Adds a modest, well-documented lift to injection resistance when combined with careful instruction placement.
Trade-offs & costs
  • Not a real security control; adversarial input can still imitate or break out of your markers.
  • Inconsistent delimiter styles within a prompt can confuse the model rather than help it.
  • Adds a small amount of markup to keep consistent across every template you maintain.
  • Section adherence is probabilistic, so the model can still occasionally cross the fence.

ExampleIn the real world

A support-ticket summarizer retrieves three past tickets and places them alongside the customer's new message. Wrapping each retrieved ticket in <context>…</context> tags and the live message in <user_message>…</user_message>, then instructing the model to summarize only what sits inside <user_message>, stops it from answering stray questions that happened to be embedded in the retrieved tickets themselves.

ToolsHow to implement it

  • Anthropic prompt engineering docsrecommend XML tags such as <document> to fence context for Claude.
  • OpenAI prompting guidessuggest triple backticks or ### headers to separate sections.
  • LangChain PromptTemplateassembles multi-part prompts with consistent, delimited slots.
  • Jinja2templating engine widely used to render prompts with clearly fenced sections.

Cost & effortWhat it takes

Effectively free at runtime — a handful of extra tokens per call, no added latency, and no infrastructure. The only real cost is the one-time effort of agreeing on a delimiter convention and applying it consistently across your prompt templates.

A living map of modern AI — kept current every morning