Service to manage library items.
Requests to the LibraryService are executed as the authenticated caller: the customer's service account (SA) when using an API key, or the user themselves when using a personal access token. Folders and items are visible according to that caller's access. The SA is a special user that is a member of the customer user group, so it sees everything shared with that group but no private folders, while a user additionally sees their own.