A library is registered under Manage Jenkins 8,793 > System > Global Trusted Pipeline Libraries with a name, a default version and a retrieval method, here Modern SCM with Git 1,932 , the repository URL and the github-booknest credential:

The Jenkinsfile asks for it by name and version. The underscore is a placeholder: an annotation must annotate something, and _ avoids a dummy import:
@Library('booknest-lib@v1.1.0') _
...
steps {
sh 'echo "Building $BRANCH_NAME at $(git rev-parse --short HEAD)"'
seedCheck()
echo "Image tag: ${imageTag()}"
}Sam committed it as b731ff1 "Load the booknest-lib shared library in the Jenkinsfile", and a scan built main:
curl -s -u "admin:$JENKINS_TOKEN" http://localhost:32080/job/booknest/job/main/3/consoleText \
| grep -E 'Loading library|Found match|seedCheck:|Image tag|^Finished'Loading library booknest-lib@v1.1.0 Found match: refs/tags/v1.1.0 revision 1de80a0f5fd9952de0c0d7e5c4ea6643ecc080f0 seedCheck: db/seed.json OK, 6 books Image tag: main-b731ff1-3 Finished: SUCCESS
The controller resolved the tag with git ls-remote, checked the library out beside the workspace (booknest_main@libs) and compiled it before the pipeline started. Load implicitly gives every pipeline the library at its default version with no annotation: a throwaway job, lib-implicit, logged "Loading library booknest-lib@v1.1.0" and the tag detached-b731ff1-1 (a plain Pipeline job has no BRANCH_NAME). The option was switched off again, because an explicit annotation shows the dependency where readers look. The library step loads a library mid-run, even at a computed version.
Global libraries are trusted: they run outside the Groovy sandbox (Script Approval), so only users with Overall/RunScripts may configure them. Libraries defined on a folder are always untrusted and sandboxed.