← All speakers

Bio, Work & Ideas

Den Delimarsky (DEVDIV)

Den Delimarsky is a member of technical staff at Anthropic and a lead maintainer of the Model Context Protocol, the open standard connecting AI systems with external tools and data. He specializes in the authorization, security, and developer experience that determine whether AI agents can safely access protected organizational systems.

From developer tools to protocol leadership

Delimarsky was already building developer tools in 2012, when he created a Windows Phone companion for Visual Studio Achievements as a Microsoft Student Insider. Across three periods at Microsoft, his work encompassed documentation infrastructure, open-source tooling, identity, and security. During his final tenure, he spent approximately two years in Microsoft Security before joining Developer Division and CoreAI in early 2025, working on authentication libraries, GitHub Copilot, developer-tool security, and MCP.

As a Microsoft principal product engineer, he served on the MCP steering committee and became a core maintainer focused on authorization and security. At AI Engineer World’s Fair 2025, he and Julia Kasper demonstrated protected MCP server architectures; Delimarsky explained the protocol’s authorization model and implemented authenticated access with its C# SDK, while Kasper demonstrated Azure API Management and VS Code integrations.

He also helped launch GitHub Spec Kit, an open-source toolkit for specification-driven development, crediting collaborator John Lam’s research in his account of leaving Microsoft.

Delimarsky joined Anthropic in January 2026 and became an MCP lead maintainer in April. He co-leads the protocol’s Security Interest Group, led its November 2025 specification release, and built a tracker for activity across MCP repositories.

  • Authorization must preserve user identity. Delimarsky helped write the MCP authorization specification, including OAuth resource indicators. His architecture separates MCP resource servers from authorization servers: established identity providers issue tokens, metadata enables authorization discovery, and protected servers validate permissions without operating their own token infrastructure.
  • Secure defaults depend on usable developer tools. His work on authentication brokers favors existing identity infrastructure, standard OAuth libraries, and framework-supported validation, making protected integrations accessible to developers who are not security specialists.
  • Indirect prompt injection crosses system boundaries. With Sarah Young, he analyzed malicious content and poisoned MCP tool descriptions, advocating trusted tool sources, supply-chain safeguards, and clear separation between authoritative instructions and untrusted external data.
  • Specifications make coding agents more accountable. His spec-driven development workflow replaces ambiguous requests with explicit requirements, technical plans, reviewable tasks, and staged verification.

His independent projects include PowerToys Awake, DeckSurf, and OpenSpartan Workshop, reflecting a continuing interest in practical software that gives developers and users greater control over their tools and data.

Read the topics behind these talks

1 conference talk

References