mitmproxy[1] in transparent mode, with a self-signed root cert added to whatever trust stores on devices/browsers/OSes you need to intercept, is where I'd start.
I'm not sure how well that copes with modern security features like cert pinning, but it's closest I can think of.
[1] https://docs.mitmproxy.org/stable/concepts-modes/#transparen...