I find hard to believe that you can decompile any app that has bothered implementing key pinning (which I always assumed is done at app level, not OS).
That aside, what's the point? There's no practical threat model where https makes what you're doing more secure. If you have neither a domain name that can use a real TLS cert nor your own CA added to the mobile device, it would be trivial for someone to MITM you. Just configure your Fedora dashboard to use http if you don't care about security